CVE-2025-70298

8.2

GPAC · GPAC

GPAC version 2.4.0 contains an out of bounds read vulnerability within the oggdmx_parse_tags function that can be triggered by a remote attacker.

Executive summary

An out of bounds read vulnerability in GPAC version 2.4.0 exposes systems to potential memory disclosure and service instability.

Vulnerability

This vulnerability is an out of bounds read flaw located in the oggdmx_parse_tags function, which allows an unauthenticated remote attacker to trigger the condition without requiring user interaction.

Business impact

The flaw carries a CVSS score of 8.2, reflecting a high severity due to its network accessibility and lack of required authentication. Successful exploitation can lead to memory leakage or denial of service conditions, potentially disrupting media processing workflows and compromising the availability of critical infrastructure relying on GPAC components.

Remediation

Immediate Action: Since no official patch is currently identified, users should restrict access to systems processing OGG files and monitor vendor channels for the release of an updated version.

Proactive Monitoring: Review application logs for crashes or unexpected termination of the GPAC process when handling OGG media files, which may indicate attempted exploitation.

Compensating Controls: Implement input validation or sandboxing for media parsing services to isolate the GPAC execution environment and limit the potential impact of memory access violations.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists, as documented in the technical write-up referenced by the CVE record.

Analyst recommendation

Given the presence of a public proof-of-concept and the high CVSS score, this vulnerability poses a significant risk to unpatched environments. Organizations should prioritize isolating affected systems and remain vigilant for vendor-supplied patches to address the underlying memory safety issue in the oggdmx_parse_tags function.

More GPAC CVEs

Sources