Impact
A double‑free flaw exists in the gf_isom_nalu_sample_rewrite function of the GPAC MP4Box utility. When the nalu_out_bs argument is processed, the routine frees the same memory block twice, corrupting heap metadata and potentially causing a program crash or undefined behavior. The weakness is categorized as CWE‑119 and CWE‑415.
Affected Systems
All GPAC builds that include the MP4Box component up to and including the 2.5‑DEV release series are affected. This includes any distribution of GPAC that deploys MP4Box. Users running these versions on any operating system are at risk when they invoke MP4Box with media files that may originate from external sources.
Risk and Exploitability
The CVSS score of 4.8 indicates a low overall severity, and the EPSS score of less than 1 % suggests a low likelihood of exploitation in the field. The vulnerability requires local execution of MP4Box; the likely attack vector is local execution of the MP4Box binary with a crafted media file, and no remote or network-based trigger is documented. The vulnerability is not listed in the CISA KEV catalog and is currently demonstrated only by a local crash proof‑of‑concept.
OpenCVE Enrichment