CVE-2025-60468

Source
https://cve.org/CVERecord?id=CVE-2025-60468
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-60468.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-60468
Downstream
Published
2026-06-24T00:00:00Z
Modified
2026-08-12T15:14:16Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

GPAC Multimedia Open Source Project GPAC Project/MP4Box 2.5-DEV-rev1593-gfe88c3545-master is affected by: Buffer Overflow. The impact is: cause a denial of service (local). The component is: filter_core/filter_pid.c (L:574-580): function gf_filter_pid_inst_swap_delete_task() improperly accesses freed objects during PID instance swap/delete cleanup, leading to heap use-after-free. The attack vector is: Local (AV:L): a local, authenticated user who processes a specially crafted MPEG-2 TS/MP4 file with MP4Box can trigger the bug during filter teardown (PID instance swap/delete), causing a crash. ΒΆΒΆ In GPAC s MP4Box, gf_filter_pid_inst_swap_delete_task() in filter_core/filter_pid.c may dereference objects after they have been freed when cleaning up PID instances after a swap/delete operation. Crafted inputs (e.g., malformed MPEG-2 TS) can trigger a heap use-after-free and crash; exploitation may be possible.

Database specific
{
    "cna_assigner": "mitre",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/60xxx/CVE-2025-60468.json"
}
References

Affected packages

Git / github.com/gpac/gpac

Affected ranges

Type
GIT
Repo
https://github.com/gpac/gpac
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Fixed
Database specific
Show details
{
    "cpe": "cpe:2.3:a:gpac:gpac:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "26.02.0"
        }
    ],
    "source": [
        "CPE_RANGE",
        "REFERENCES"
    ]
}

Affected versions

Other
abi-12
abi-13
abi-14
abi-15
abi-16
abi-12.*
abi-12.16
abi-12.17
abi-12.18
abi-12.19
abi-12.20
abi-12.21
abi-12.22
abi-12.23
abi-12.24
abi-12.25
abi-12.26
abi-12.27
abi-13.*
abi-13.0
abi-14.*
abi-14.0
abi-15.*
abi-15.0
abi-15.1
abi-15.2
abi-16.*
abi-16.2
abi-16.3
abi-16.4
abi-16.5
testtag0.*
testtag0.1
v0.*
v0.5.2
v0.6.0
v0.9.0
v0.9.0-preview
v1.*
v1.0.0
v2.*
v2.0.0
v2.2.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-60468.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "function_hash": "219671961627737591255376287579616607644",
            "length": 13699
        },
        "id": "CVE-2025-60468-061f5613",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/gpac/gpac/commit/976dacf65cb6986a4e4f350fb8d3ed0a17dc3a77",
        "target": {
            "file": "src/filter_core/filter_pid.c",
            "function": "gf_filter_pid_configure"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "297175128717300816504741722694927441064",
            "length": 3584
        },
        "id": "CVE-2025-60468-38ffd1df",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/gpac/gpac/commit/aed9c94e92e8ba362ddb29c767c519478f46f195",
        "target": {
            "file": "src/filter_core/filter.c",
            "function": "gf_filter_renegotiate_output_dst"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "262155974231866136705572185965789161126",
                "12135805869119536206460201203284214942",
                "153951549916381686425568984062057108414",
                "279892742734582357656427043874621701739",
                "186792266941436477136034478908457461076",
                "193342806623947448591048957981834427375",
                "109009591829251661701057026313046233625",
                "154149014177554181014932223901106559222",
                "161972567249451686033038187977928474459",
                "101572986208497586617601621685098200801"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2025-60468-4921f0c4",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/gpac/gpac/commit/aed9c94e92e8ba362ddb29c767c519478f46f195",
        "target": {
            "file": "src/filter_core/filter_session.h"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "163822833403614273231760070918713284887",
            "length": 16445
        },
        "id": "CVE-2025-60468-5f38bdc6",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/gpac/gpac/commit/aed9c94e92e8ba362ddb29c767c519478f46f195",
        "target": {
            "file": "src/filter_core/filter_pck.c",
            "function": "gf_filter_pck_send_internal"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "232147217875205470120919427846487436807",
                "166120396089686534191855413696671950028",
                "30531686057703166772423336569652330487",
                "234464364727780498829665960838629090244"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2025-60468-9307c62b",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/gpac/gpac/commit/aed9c94e92e8ba362ddb29c767c519478f46f195",
        "target": {
            "file": "src/filter_core/filter.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "115801882196588680133056929168323747667",
                "107057327739275687434794124097556529645",
                "79758268100699590034943448011008970310",
                "71884385134001509545765922910896754927",
                "214408138922202034313284350008879496435",
                "220521384289801553340089018319946812379",
                "223174539770309222108734749245546688220"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2025-60468-ef483ca3",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/gpac/gpac/commit/976dacf65cb6986a4e4f350fb8d3ed0a17dc3a77",
        "target": {
            "file": "src/filter_core/filter_pid.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "108888468866378775050974501103875106242",
                "36455544046464676073878363220687755696",
                "4061688473031700282518817597810409963",
                "22633018408560489296397765411773610932",
                "288454874074594117895008252519323988724",
                "131092049465543512821227294226860226473",
                "111506376734668308919831112916919115488",
                "64752133816386244939917517270722609999"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2025-60468-f7983e21",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/gpac/gpac/commit/aed9c94e92e8ba362ddb29c767c519478f46f195",
        "target": {
            "file": "src/filter_core/filter_pck.c"
        }
    }
]
vanir_signatures_modified
"2026-08-12T15:14:16Z"