Security Advisory 2026-0083 (CVE-2026-86476)
|
|
| Summary |
Out-of-bounds read and write in GStreamer video meta deserialization |
| Date |
2026-10-08 |
| Affected Versions |
GStreamer core < 1.28.8, GStreamer gst-plugins-base < 1.28.8 |
| IDs |
GStreamer-SA-2026-0083 CVE-2026-86476 |
Details
When deserializing video metadata, for example as received from an untrusted
network source or another, untrusted process (e.g. via the unixfd plugin),
GStreamer did not validate the described frame geometry. A
crafted serialized video meta could declare plane offsets and strides that
extend beyond the buffer's actual memory, or negative strides. An application
that subsequently maps or copies the video frame described by such metadata
would perform out-of-bounds reads and writes on the heap.
Similar issues in the deserialization of audio metadata and reference
timestamp metadata, which could lead to out-of-bounds memory access or a
crash, have also been fixed.
Impact
A malicious third party could trigger out-of-bounds reads and writes to heap
memory by providing crafted serialized video metadata, potentially resulting
in a crash, data corruption, or arbitrary code execution.
Solution
The GStreamer 1.28.8 release addresses the issue. People using older versions
of GStreamer should apply the patch and recompile.
References
The GStreamer project
CVE Database Entries
GStreamer 1.28.8 release
Patches