https://seclists.org/oss-sec/2026/q2/917: CVE-2025-55659: NULL Pointer Defence in GPAC/MP4Box via ctts_box_write on crafted MP4 file with negative timestamps
Published Jun 13, 2026
·Updated
Affected Software
1 affected component
Gpac MP4Box<ff8249a407685d00ceb5f4d2a798b9cad195140e
Frequently Asked Questions
1
What is the severity of CVE-2025-55659?
The severity of CVE-2025-55659 is classified as Medium with a CVSS score of 4.3.
2
How do I fix CVE-2025-55659?
You can fix CVE-2025-55659 by updating GPAC (MP4Box) to the version including the fix from commit ff8249a407685d00ceb5f4d2a798b9cad195140e.
3
What systems are affected by CVE-2025-55659?
CVE-2025-55659 affects GPAC (MP4Box) versions prior to the fix commit specified.
4
What type of vulnerability is CVE-2025-55659?
CVE-2025-55659 is classified as a NULL Pointer Dereference vulnerability (CWE-476).
5
What is the impact of CVE-2025-55659?
The impact of CVE-2025-55659 can lead to application crashes when handling crafted MP4 files with negative timestamps.