https://seclists.org/oss-sec/2026/q2/918: CVE-2025-55651: NULL Pointer Defence in GPAC/MP4Box via gf_isom_get_user_data_count on truncated MP4 input
Published Jun 13, 2026
·Updated
Affected Software
1 affected component
Gpac MP4Box<46be5f928660530d5332cd2f1d177208737558ef
Frequently Asked Questions
1
What is the severity of CVE-2025-55651?
The severity of CVE-2025-55651 is rated as medium with a CVSS score of 4.3.
2
How do I fix CVE-2025-55651?
To fix CVE-2025-55651, update to the GPAC (MP4Box) version that includes the fix from commit 46be5f928660530d5332cd2f1d177208737558ef.
3
What type of vulnerability is CVE-2025-55651?
CVE-2025-55651 is a NULL Pointer Dereference vulnerability identified by CWE-476.
4
Which versions of GPAC are affected by CVE-2025-55651?
GPAC (MP4Box) versions prior to the fix commit are affected by CVE-2025-55651.
5
What can happen if CVE-2025-55651 is exploited?
Exploiting CVE-2025-55651 can lead to application crashes due to the NULL pointer dereference.