Security Advisory 2026-0085
|
|
| Summary |
Stack-based out-of-bounds write in closed caption converter and combiner |
| Date |
2026-10-08 |
| Affected Versions |
GStreamer gst-plugins-bad < 1.28.8 |
| IDs |
GStreamer-SA-2026-0085 |
Details
The closed caption converter and combiner elements in gst-plugins-bad copy
incoming closed caption data into fixed-size internal buffers without
validating the data length. Crafted CEA708 closed caption data longer than the
maximum expected size causes a stack-based out-of-bounds write when converted
by ccconverter or combined by cccombiner. Additionally, when cccombiner
processes CEA608 closed caption data in SMPTE S334-1A format, it appends the
input data to fixed-size internal buffers per field without validating the
length, and crafted input longer than the maximum expected size causes a
stack-based out-of-bounds write.
Impact
A malicious third party could trigger a stack-based out-of-bounds write by
providing crafted media data containing oversized CEA708 or CEA608 (S334-1A
format) closed caption data, potentially resulting in a crash, denial of
service, or arbitrary code execution.
Solution
The gst-plugins-bad 1.28.8 release addresses the issue. People using older
versions of GStreamer should apply the patch and recompile.
References
The GStreamer project
CVE Database Entries
- No CVE number assigned or pending
GStreamer 1.28.8 release
Patches