https://seclists.org/oss-sec/2026/q2/1041: CVE-2025-60466: Expid Pointer Defence in GPAC/MP4Box via gf_filter_pid_get_packet on crafted MPEG-2 TS file
Published Jun 26, 2026
·Updated
Affected Software
1 affected component
Gpac MP4Box
Frequently Asked Questions
1
What is the severity of CVE-2025-60466?
CVE-2025-60466 has a CVSS score of 4.3, indicating a medium severity level.
2
How do I fix CVE-2025-60466?
To fix CVE-2025-60466, you need to update GPAC (MP4Box) to the latest version that includes the fix.
3
What type of vulnerability is CVE-2025-60466?
CVE-2025-60466 is classified as an Expired Pointer Dereference vulnerability.
4
Which versions of GPAC are affected by CVE-2025-60466?
GPAC versions prior to the fix commit are affected by CVE-2025-60466.
5
What is the impact of exploiting CVE-2025-60466?
Exploitation of CVE-2025-60466 may lead to a denial of service due to application crashes.