https://seclists.org/oss-sec/2026/q2/1034: CVE-2025-60471: Use-After-Fe in GPAC/MP4Box via gf_filter_pid_configu_task_discard on crafted MPEG-2 TS file
Published Jun 26, 2026
·Updated
Affected Software
1 affected component
Gpac GPAC (MP4Box)<62714f27c64a3d1eb7e880f9eed2d38673cb43ce
Frequently Asked Questions
1
What is the severity of CVE-2025-60471?
CVE-2025-60471 has a CVSS score of 8.8, indicating it is a high severity vulnerability.
2
How do I fix CVE-2025-60471?
To fix CVE-2025-60471, update to GPAC (MP4Box) version after commit 62714f27c64a3d1eb7e880f9eed2d38673cb43ce.
3
What type of vulnerability is CVE-2025-60471?
CVE-2025-60471 is categorized as a Use-After-Free vulnerability, specifically listed under CWE-416.
4
What products are affected by CVE-2025-60471?
CVE-2025-60471 affects GPAC (MP4Box) versions prior to the fix commit.
5
What does CVE-2025-60471 exploit?
CVE-2025-60471 can be exploited via crafted MPEG-2 TS files that trigger the vulnerability in the gf_filter_pid_configu_task_discard function.