https://seclists.org/oss-sec/2026/q2/773: CVE-2025-60486: Use-After-Fe in GPAC/MP4Box via dasher_process on crafted MPEG-2 TS file
Published Jun 1, 2026
·Updated
Affected Software
1 affected component
Gpac GPAC (MP4Box)<2.5-DEV-rev1665-g3f20eb0cd-master
Frequently Asked Questions
1
What is the severity of CVE-2025-60486?
CVE-2025-60486 has a CVSS score of 8.8, classifying it as a high severity vulnerability.
2
What vulnerability type is associated with CVE-2025-60486?
CVE-2025-60486 is categorized as a Use After Free vulnerability, specifically identified as CWE-416.
3
How do I fix CVE-2025-60486?
To mitigate CVE-2025-60486, update to GPAC version 2.5-DEV-rev1665-g3f20eb0cd-master or later.
4
Which software is affected by CVE-2025-60486?
CVE-2025-60486 affects GPAC (MP4Box) versions prior to the fix in commit 3f20eb0cd22116367c036e6ffe6ace299b38d686.
5
What are the potential impacts of CVE-2025-60486?
Exploitation of CVE-2025-60486 could lead to denial of service and potential remote code execution due to memory corruption.