GStreamer
open source multimedia framework

GStreamer Conference 2026

10-11 October 2026 ยท Prague, Czech Republic

Join us!
Home
Features
News
Annual Conference
Planet (Blogs)
Download
Applications
Security Center
GitLab
Developers
Documentation
Forum
File a Bug
Artwork
Follow us on Bluesky
Follow us on Mastodon
Chat with us on Matrix

Security Advisory 2026-0089

Summary Integer overflow and out-of-bounds read in Matroska demuxer Xiph codec data parser
Date 2026-10-08
Affected Versions GStreamer gst-plugins-good < 1.28.8
IDs GStreamer-SA-2026-0089

Details

An integer overflow vulnerability in the Xiph stream header parser of the Matroska (MKV/WebM) demuxer in gst-plugins-good. The parser decodes packet lengths from the codec private data of Vorbis audio, Theora video, and Kate tracks using a variable-length encoding, accumulating the lengths in 32-bit integer arithmetic. A crafted file can make the accumulated length wrap around, causing the offset plus length sum used by the bounds check to appear smaller than it actually is and bypassing the check. The demuxer then copies the declared packet length starting from a position at the end of the codec private data buffer, resulting in a large out-of-bounds heap read.

Impact

A malicious third party could trigger an out-of-bounds heap read by providing a crafted Matroska or WebM file containing a Vorbis audio, Theora video, or Kate track with manipulated codec private data. This can result in application crash, denial of service, or information disclosure. Since the Matroska demuxer is auto-plugged by playbin, decodebin, and gst-discoverer pipelines, merely opening or previewing such a file is sufficient to trigger the vulnerability.

Solution

The gst-plugins-good 1.28.8 release addresses the issue. People using older versions of GStreamer should apply the patch and recompile.

References

The GStreamer project

CVE Database Entries

  • No CVE number assigned or pending

GStreamer 1.28.8 release

Patches


Report a problem on this page.