{"id":"CVE-2025-60464","details":"A use-after-free in the gf_sei_load_from_state_internal function (/filters/sei_load.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MPEG-2 TS file.","modified":"2026-08-12T15:14:17.262030Z","published":"2026-06-25T00:00:00Z","database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/60xxx/CVE-2025-60464.json"},"references":[{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2026/06/26/4"},{"type":"WEB","url":"https://github.com/sigdevel/pocs/blob/main/res/gpac/MP4Box/32/32_filters_sei_load_c_225_in_gf_sei_load_from_state_internal"},{"type":"WEB","url":"https://github.com/sigdevel/pocs/blob/main/res/gpac/MP4Box/32/README.md"},{"type":"WEB","url":"https://infosec.exchange/@sigdevel/116778370895014131"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/60xxx/CVE-2025-60464.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-60464"},{"type":"REPORT","url":"https://github.com/gpac/gpac/issues/3278"},{"type":"FIX","url":"https://github.com/gpac/gpac/commit/8f404bd581e455267482f86272169a742f654b97"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/gpac/gpac","events":[{"introduced":"0"},{"fixed":"118e60a905878e56dc4f9c5b309143c5f447c702"},{"fixed":"8f404bd581e455267482f86272169a742f654b97"}],"database_specific":{"cpe":"cpe:2.3:a:gpac:gpac:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"26.02.0"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["abi-16.5","abi-16.4","abi-16.3","abi-16.2","abi-16","abi-15.2","abi-15.1","abi-15.0","abi-15","abi-14.0","abi-14","abi-13.0","abi-13","abi-12.27","abi-12.26","abi-12.25","abi-12.24","abi-12.23","abi-12.22","abi-12.21","abi-12.20","abi-12.19","abi-12.18","abi-12.17","abi-12.16","abi-12","testtag0.1","v2.2.0","v2.0.0","v1.0.0","v0.9.0","v0.9.0-preview","v0.6.0","v0.5.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-60464.json","vanir_signatures_modified":"2026-08-12T15:14:17Z","vanir_signatures":[{"digest":{"function_hash":"49693748215693631872447578373367731882","length":2616},"id":"CVE-2025-60464-ed77e975","signature_type":"Function","signature_version":"v1","source":"https://github.com/gpac/gpac/commit/8f404bd581e455267482f86272169a742f654b97","target":{"file":"src/filters/sei_load.c","function":"seiloader_set_type"},"deprecated":false},{"target":{"file":"src/filters/sei_load.c"},"deprecated":false,"digest":{"line_hashes":["54792072329502583052370657150482281222","113923329731236963033572983632798500881","206858496126925950541822729101194197724","321637923236465046872521867390539641084","184481426072328363434304090534559702060","154524781352436352901985007946385011926","97576296246524286410891166237169323730","306799349474881298798766346406975687051","72331594068485451104336984536319707135","175391239003993196981560632092618505037","151340973027622855503437008397189476882","178784446274947581424476429123048410650","275388182899313653723601035851493758113","243542334422085899996538879437529848032","151367242797750246189344950861852274576","80266027288644848331591874278803988859","219972307940994528440024836233884791120","203295302110420639760100719965040945713","73263355130085709009943253428318406513","171449230873672252940110685513815487068","118462360540725295586593356078498144908","231747856280199105318158645333291259569","174952797109196690714240755663370764146","321757284596049259956722928714954068603","258902321437331716181938073257612941125","83648310624598573148890930103785342358","99721285489233092319368193747113489014","233626963259921174673022671199876306347","94641407082508893881389154958109956124","299167444091132589636408359192640054363","175798834561779079314730921442743265175","232199088620166765547838654644862893259","173067835095402200427527725228661772422","254934527417496114130874234696831255352","82448035537794225111816737789465452801"],"threshold":0.9},"id":"CVE-2025-60464-f0bbd833","signature_type":"Line","signature_version":"v1","source":"https://github.com/gpac/gpac/commit/8f404bd581e455267482f86272169a742f654b97"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}