https://seclists.org/oss-sec/2026/q2/920: CVE-2025-55662: Divide by Zero in GPAC/MP4Box via gf_opus_parse_packet_header on crafted MP4 file with malformed Opus header
Published Jun 13, 2026
·Updated
Affected Software
1 affected component
Gpac GPAC (MP4Box)<ff8249a407685d00ceb5f4d2a798b9cad195140e
Frequently Asked Questions
1
What is the severity of CVE-2025-55662?
CVE-2025-55662 has a CVSS score of 4.3, indicating a medium severity level.
2
How do I fix CVE-2025-55662?
To fix CVE-2025-55662, update GPAC (MP4Box) to the latest version that includes the fix commit ff8249a407685d00ceb5f4d2a798b9cad195140e.
3
What causes the vulnerability CVE-2025-55662?
CVE-2025-55662 is caused by a divide by zero error in the gf_opus_parse_packet_header function when processing crafted MP4 files with malformed Opus headers.
4
What are the potential impacts of CVE-2025-55662?
The potential impact of CVE-2025-55662 includes application crashes or denial of service due to the divide by zero error.
5
Which versions of GPAC are affected by CVE-2025-55662?
CVE-2025-55662 affects all versions of GPAC prior to the fix commit ff8249a407685d00ceb5f4d2a798b9cad195140e.