A vulnerability was determined in GPAC up to 2.5-DEV. This vulnerability affects the function gfisomnalusamplerewrite of the file src/isomedia/avcext.c of the component MP4Box. This manipulation of the argument naluout_bs causes double free. It is possible to launch the attack on the local host. The exploit has been publicly disclosed and may be utilized. Patch name: f29f955f2a3b5e8e507caad3e52319f961bf37bf. To fix this issue, it is recommended to deploy a patch.
{
"cwe_ids": [
"CWE-119",
"CWE-415"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/15xxx/CVE-2025-15667.json",
"cna_assigner": "VulDB",
"unresolved_ranges": [
{
"source": "AFFECTED_FIELD",
"extracted_events": [
{
"introduced": "2.5-DEV"
},
{
"last_affected": "2.5-DEV"
}
]
}
]
}"2026-07-15T15:33:04Z"
[
{
"signature_type": "Function",
"target": {
"file": "src/isomedia/box_code_base.c",
"function": "sgpd_del_entry"
},
"deprecated": false,
"source": "https://github.com/gpac/gpac/commit/f29f955f2a3b5e8e507caad3e52319f961bf37bf",
"id": "CVE-2025-15667-cc4778a8",
"signature_version": "v1",
"digest": {
"function_hash": "129067690988058699157575606452399646472",
"length": 1239.0
}
},
{
"signature_type": "Line",
"target": {
"file": "src/isomedia/box_code_base.c"
},
"deprecated": false,
"source": "https://github.com/gpac/gpac/commit/f29f955f2a3b5e8e507caad3e52319f961bf37bf",
"id": "CVE-2025-15667-ce158ecb",
"signature_version": "v1",
"digest": {
"line_hashes": [
"262007496686185893720648064013500846942",
"27753409557248353458459677581086461513",
"229811521048158137593256894815118330857",
"140328879052536668385729807330563239281"
],
"threshold": 0.9
}
},
{
"signature_type": "Function",
"target": {
"file": "src/isomedia/avc_ext.c",
"function": "gf_isom_nalu_sample_rewrite"
},
"deprecated": false,
"source": "https://github.com/gpac/gpac/commit/f29f955f2a3b5e8e507caad3e52319f961bf37bf",
"id": "CVE-2025-15667-d1460444",
"signature_version": "v1",
"digest": {
"function_hash": "339252933352634881394757964469972119315",
"length": 13788.0
}
},
{
"signature_type": "Line",
"target": {
"file": "src/isomedia/avc_ext.c"
},
"deprecated": false,
"source": "https://github.com/gpac/gpac/commit/f29f955f2a3b5e8e507caad3e52319f961bf37bf",
"id": "CVE-2025-15667-d3ae9dbf",
"signature_version": "v1",
"digest": {
"line_hashes": [
"334047503270733182863224688911913477926",
"78553545245786605548197931512013542130",
"148983692273964010015876554924893397653"
],
"threshold": 0.9
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-15667.json"