A NULL pointer dereference in GPAC MP4Box: when parsing certain truncated MP4 files, an unknown/invalid stsd entry can result in missing descriptor fields (e.g., codec/mime/profile strings). gf_media_map_esd then calls strlen() on a NULL pointer, triggering a crash (ASan SEGV).
Metrics
Affected Vendors & Products
References
History
Wed, 27 May 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A NULL pointer dereference in GPAC MP4Box: when parsing certain truncated MP4 files, an unknown/invalid stsd entry can result in missing descriptor fields (e.g., codec/mime/profile strings). gf_media_map_esd then calls strlen() on a NULL pointer, triggering a crash (ASan SEGV). | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-05-27T16:20:53.118Z
Reserved: 2026-01-09T00:00:00.000Z
Link: CVE-2025-70116
No data.
Status : Received
Published: 2026-05-27T17:16:29.187
Modified: 2026-05-27T17:16:29.187
Link: CVE-2025-70116
No data.
OpenCVE Enrichment
No data.