CVE-2025-70309: Medium severity Gpac GPAC vulnerability
Published Jan 15, 2026
·Updated
A stack overflow in the pcmreframeflushpacket function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted WAV file.
Affected Software
2 affected components
Gpac GPAC
Gpac GPAC=2.4.0
Event History
Jan 15, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-70309?
CVE-2025-70309 has a severity rating that indicates a significant risk of Denial of Service (DoS) due to a stack overflow.
2
How do I fix CVE-2025-70309?
To mitigate CVE-2025-70309, upgrade to the latest version of GPAC that addresses this vulnerability.
3
What type of attack does CVE-2025-70309 facilitate?
CVE-2025-70309 can be exploited to conduct a Denial of Service (DoS) attack via specially crafted WAV files.
4
Which software versions are affected by CVE-2025-70309?
GPAC version 2.4.0 is the affected version for CVE-2025-70309.
5
Can CVE-2025-70309 lead to data loss?
While CVE-2025-70309 primarily affects availability by causing a DoS, it may indirectly lead to data loss due to system crashes.