https://seclists.org/oss-sec/2026/q2/916: CVE-2025-55657: NULL Pointer Defence in GPAC/MP4Box via gf_odf_vvc_cfg_write_bs on crafted MP4 file with unsupported vvc16 box
Published Jun 13, 2026
·Updated
Affected Software
1 affected component
Gpac MP4Box<ff8249a407685d00ceb5f4d2a798b9cad195140e
Frequently Asked Questions
1
What is the severity of CVE-2025-55657?
CVE-2025-55657 has a CVSS score of 4.3, classified as MEDIUM severity.
2
What products are affected by CVE-2025-55657?
CVE-2025-55657 affects GPAC (MP4Box) versions prior to the fix commit ff8249a407685d00ceb5f4d2a798b9cad195140e.
3
How do I fix CVE-2025-55657?
To fix CVE-2025-55657, you should update your GPAC (MP4Box) installation to the version that contains the fix commit ff8249a407685d00ceb5f4d2a798b9cad195140e or later.
4
What type of vulnerability is CVE-2025-55657?
CVE-2025-55657 is classified as a NULL Pointer Dereference under CWE-476.
5
How does CVE-2025-55657 affect GPAC/MP4Box?
CVE-2025-55657 can lead to a NULL pointer dereference when processing crafted MP4 files with unsupported vvc16 boxes.