CVE-2025-55643

medium
Published 2026-06-15 Β· Modified 2026-06-15
CVSS v3
5.5
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS v4 NEW
β€”
not yet in upstream
VIR risk
5.5

Description

A NULL pointer dereference in the TrackWriter handling component (filters/mux_isom.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.

Predictions

Exploit likelihood
55%
Patch ETA
β€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Debian Security Tracker Β· View original β†— Β· DFSG

CVE-2025-55643 NameCVE-2025-55643 SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) Vulnerable and fixed packages The table below lists information on source packages. Source PackageReleaseVersionStatus gpac (PTS)bullseye (security), bullseye1.0.1+dfsg1-4+deb11u3vulnerable The…

CVE-2025-55643

NameCVE-2025-55643
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
gpac (PTS)bullseye (security), bullseye1.0.1+dfsg1-4+deb11u3vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
gpacsourcebullseye(unfixed)end-of-life
gpacsource(unstable)(unfixed)

Notes

[bullseye] - gpac <end-of-life> (out of LTS support)

Home - Debian Security - Source (Git)

Apply commands

text fix
Notes
[bullseye] - gpac <end-of-life> (out of LTS support)

OS impact

debian Debian Affected 1 release
VersionStatusFixed in
bullseye Affected β€”

References

CWEs

CWE-476

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.