Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 25 Jun 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | GPAC MP4Box Heap Use‑After‑Free via PID Instance Swap/Delete |
Thu, 25 Jun 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Buffer Overflow Causing Local Denial of Service in GPAC MP4Box | |
| Weaknesses | CWE-416 |
Thu, 25 Jun 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Thu, 25 Jun 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gpac
Gpac mp4box |
|
| Vendors & Products |
Gpac
Gpac mp4box |
Thu, 25 Jun 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Buffer Overflow Causing Local Denial of Service in GPAC MP4Box | |
| Weaknesses | CWE-122 CWE-416 |
Wed, 24 Jun 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GPAC Multimedia Open Source Project GPAC Project/MP4Box 2.5-DEV-rev1593-gfe88c3545-master is affected by: Buffer Overflow. The impact is: cause a denial of service (local). The component is: filter_core/filter_pid.c (L:574-580): function gf_filter_pid_inst_swap_delete_task() improperly accesses freed objects during PID instance swap/delete cleanup, leading to heap use-after-free. The attack vector is: Local (AV:L): a local, authenticated user who processes a specially crafted MPEG-2 TS/MP4 file with MP4Box can trigger the bug during filter teardown (PID instance swap/delete), causing a crash. ¶¶ In GPAC s MP4Box, gf_filter_pid_inst_swap_delete_task() in filter_core/filter_pid.c may dereference objects after they have been freed when cleaning up PID instances after a swap/delete operation. Crafted inputs (e.g., malformed MPEG-2 TS) can trigger a heap use-after-free and crash; exploitation may be possible. | |
| References |
|
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-06-25T13:33:58.397Z
Reserved: 2025-09-26T00:00:00.000Z
Link: CVE-2025-60468
Updated: 2026-06-25T13:31:11.373Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-25T18:15:04Z