CVE-2020-11558
NixOS vulnerability analysis and mitigation

Overview

An issue was discovered in libgpac.a in GPAC 0.8.0, as demonstrated by MP4Box. The audio_sample_entry_Read function in isomedia/box_code_base.c does not properly decide when to make gf_isom_box_del calls, leading to various use-after-free outcomes involving mdia_Read, gf_isom_delete_movie, and gf_isom_parse_movie_boxes (NVD).

Technical details

The vulnerability exists in the audio_sample_entry_Read function within the isomedia/box_code_base.c file. The issue stems from improper handling of memory deallocation calls through gf_isom_box_del, which results in use-after-free conditions. This affects the processing of MP4 files when using the MP4Box utility (GitHub Commit).

Impact

The vulnerability can lead to various use-after-free outcomes when processing MP4 files, potentially resulting in program crashes or arbitrary code execution. The issue affects the core functionality of GPAC's media processing capabilities (NVD).

Mitigation and workarounds

The issue has been fixed in a subsequent patch that modifies the audio_sample_entry_Read function to properly handle memory deallocation. Users should upgrade to a version of GPAC that includes this fix (GitHub Commit).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-20807MEDIUM6.7
  • NixOSNixOS
  • android
NoNoJan 06, 2026
CVE-2025-20806MEDIUM6.7
  • NixOSNixOS
  • android
NoNoJan 06, 2026
CVE-2025-20805MEDIUM6.7
  • NixOSNixOS
  • android
NoNoJan 06, 2026
CVE-2025-20804MEDIUM6.7
  • NixOSNixOS
  • android
NoNoJan 06, 2026
CVE-2025-20803MEDIUM6.7
  • NixOSNixOS
  • android
NoNoJan 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management