Security Advisory 2026-0089
|
|
| Summary |
Integer overflow and out-of-bounds read in Matroska demuxer Xiph codec data parser |
| Date |
2026-10-08 |
| Affected Versions |
GStreamer gst-plugins-good < 1.28.8 |
| IDs |
GStreamer-SA-2026-0089 |
Details
An integer overflow vulnerability in the Xiph stream header parser of the
Matroska (MKV/WebM) demuxer in gst-plugins-good. The parser decodes packet
lengths from the codec private data of Vorbis audio, Theora video, and Kate
tracks using a variable-length encoding, accumulating the lengths in 32-bit
integer arithmetic. A crafted file can make the accumulated length wrap
around, causing the offset plus length sum used by the bounds check to appear
smaller than it actually is and bypassing the check. The demuxer then copies
the declared packet length starting from a position at the end of the codec
private data buffer, resulting in a large out-of-bounds heap read.
Impact
A malicious third party could trigger an out-of-bounds heap read by providing
a crafted Matroska or WebM file containing a Vorbis audio, Theora video, or
Kate track with manipulated codec private data. This can result in application
crash, denial of service, or information disclosure. Since the Matroska
demuxer is auto-plugged by playbin, decodebin, and gst-discoverer pipelines,
merely opening or previewing such a file is sufficient to trigger the
vulnerability.
Solution
The gst-plugins-good 1.28.8 release addresses the issue. People using older
versions of GStreamer should apply the patch and recompile.
References
The GStreamer project
CVE Database Entries
- No CVE number assigned or pending
GStreamer 1.28.8 release
Patches