CVE-2025-70298: High severity Gpac GPAC vulnerability
Published Jan 15, 2026
·Updated
GPAC v2.4.0 was discovered to contain an out-of-bounds read in the oggdmxparsetags function.
Affected Software
2 affected components
Gpac GPAC
Gpac GPAC=2.4.0
Event History
Jan 15, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-70298?
CVE-2025-70298 is classified as a potential high severity vulnerability due to its out-of-bounds read in the GPAC software.
2
How do I fix CVE-2025-70298?
To fix CVE-2025-70298, you should update to the latest version of GPAC that addresses this vulnerability.
3
What is the impact of CVE-2025-70298?
The impact of CVE-2025-70298 may lead to information disclosure and potential application instability due to the out-of-bounds read.
4
Which versions of GPAC are affected by CVE-2025-70298?
CVE-2025-70298 affects GPAC version 2.4.0; earlier versions may also be affected.
5
How can I determine if my system is vulnerable to CVE-2025-70298?
You can determine if your system is vulnerable to CVE-2025-70298 by checking the installed version of GPAC and looking for any security updates.