Security Advisory 2026-0008 (CVE-2026-3083, CVE-2026-3085, ZDI-CAN-28851, ZDI-CAN-28850)
|
|
| Summary |
Multiple vulnerabilities in RTP QDM2 depayloader element |
| Date |
2026-02-25 |
| Affected Versions |
GStreamer gst-plugins-good 1.28 < 1.28.1 , GStreamer gst-plugins-good 1.x <= 1.28.10 |
| IDs |
GStreamer-SA-2026-0008 CVE-2026-3083 CVE-2026-3085 ZDI-CAN-28851 ZDI-CAN-28850 |
Details
Heap-based buffer overflow and out-of-bounds write in the RTP QDM2 depayloader.
Impact
It is possible for a malicious third party to trigger a heap overflow or
out-of-bounds write that can result in a crash of the application, possibly
even remote execution.
Solution
The gst-plugins-good 1.28.1 release addresses the issue. People using older
versions of GStreamer should apply the patch and recompile.
References
The GStreamer project
CVE Database Entries
GStreamer releases
1.28 (current stable)
Patches