https://seclists.org/oss-sec/2026/q2/921: CVE-2025-52292: Stack-based Buffer Overflow in GPAC/MP4Box via filein_process on crafted MP4 file during DASH segmentation
Published Jun 13, 2026
·Updated
Affected Software
1 affected component
Gpac MP4Box<2.5-DEV-rev1174-g3017379f1-master
Frequently Asked Questions
1
What is the severity of CVE-2025-52292?
CVE-2025-52292 has a CVSS 3.1 score of 8.8, indicating a HIGH severity vulnerability.
2
How do I fix CVE-2025-52292?
To fix CVE-2025-52292, update GPAC/MP4Box to the version after commit 2.5-DEV-rev1174-g3017379f1-master.
3
What type of vulnerability is CVE-2025-52292?
CVE-2025-52292 is a stack-based buffer overflow vulnerability found in GPAC/MP4Box.
4
When was CVE-2025-52292 published?
CVE-2025-52292 was published on June 13, 2026.
5
What can be impacted by CVE-2025-52292?
CVE-2025-52292 can potentially allow an attacker to achieve high levels of confidentiality, integrity, and availability impact.