https://seclists.org/oss-sec/2026/q2/1033: CVE-2025-55639: NULL Pointer Defence in GPAC/MP4Box via gf_isom_add_track_kind on crafted MP4 file
Published Jun 26, 2026
·Updated
Affected Software
1 affected component
Gpac gpac/MP4Box<78c2c9be29a41b38eca2c53d280442088a71dab9
Frequently Asked Questions
1
What is the severity of CVE-2025-55639?
CVE-2025-55639 has a CVSS 3.1 score of 4.3, classified as a MEDIUM severity vulnerability.
2
How do I fix CVE-2025-55639?
To fix CVE-2025-55639, update to the GPAC version that includes the fix commit 78c2c9be29a41b38eca2c53d280442088a71dab9.
3
What is the impact of CVE-2025-55639?
CVE-2025-55639 can lead to a NULL Pointer Dereference, potentially causing application crashes when processing crafted MP4 files.
4
Which versions of GPAC are affected by CVE-2025-55639?
GPAC versions prior to the fix commit 78c2c9be29a41b38eca2c53d280442088a71dab9 are affected by CVE-2025-55639.
5
Who reported CVE-2025-55639?
CVE-2025-55639 was reported by a security researcher known as sigdevel.