https://seclists.org/oss-sec/2026/q2/1035: CVE-2025-60464: NULL Pointer Defence in GPAC/MP4Box via gf_sei_load_from_state_internal on crafted MPEG-2 TS file
Published Jun 26, 2026
·Updated
Affected Software
1 affected component
Gpac MP4Box<fix commit 62714f27c64a3d1eb7e880f9eed2d38673cb43ce
Frequently Asked Questions
1
What is the severity of CVE-2025-60464?
CVE-2025-60464 has a CVSS score of 4.3, indicating a medium severity level.
2
How do I fix CVE-2025-60464?
To fix CVE-2025-60464, update GPAC (MP4Box) to the version following the fix commit 62714f27c64a3d1eb7e880f9eed2d38673cb43ce.
3
What type of vulnerability is CVE-2025-60464?
CVE-2025-60464 is a NULL pointer dereference vulnerability as per CWE-476.
4
Which product is affected by CVE-2025-60464?
CVE-2025-60464 affects GPAC (MP4Box) prior to the specific fix commit.
5
How does CVE-2025-60464 impact systems?
CVE-2025-60464 can lead to application crashes when processing crafted MPEG-2 TS files.