https://seclists.org/oss-sec/2026/q2/1040: CVE-2025-60465: Use-After-Fe in GPAC/MP4Box via gf_filter_pid_inst_swap on crafted MPEG-2 TS file
Published Jun 26, 2026
·Updated
Affected Software
1 affected component
Gpac GPAC (MP4Box)<fix commit (not specified)
Frequently Asked Questions
1
What is the severity of CVE-2025-60465?
CVE-2025-60465 has been rated with a CVSS score of 4.3, indicating a medium severity level.
2
How do I fix CVE-2025-60465?
To fix CVE-2025-60465, update to the latest version of GPAC (MP4Box) as specified in the fix commit.
3
What type of vulnerability is CVE-2025-60465?
CVE-2025-60465 is classified as a Use-After-Free vulnerability according to CWE-416.
4
What is affected by CVE-2025-60465?
CVE-2025-60465 affects GPAC (MP4Box) versions prior to the fix commit.
5
What causes CVE-2025-60465?
CVE-2025-60465 is caused by a flaw in the gf_filter_pid_inst_swap() function when handling crafted MPEG-2 TS files.