Security Advisory 2026-0091
|
|
| Summary |
Out-of-bounds read in RTCP SDES privately defined entry handling |
| Date |
2026-10-08 |
| Affected Versions |
GStreamer gst-plugins-good < 1.28.8 |
| IDs |
GStreamer-SA-2026-0091 |
Details
An out-of-bounds read vulnerability in the RTP session handling of
gst-plugins-good, which processes incoming RTCP (RTP Control Protocol)
packets. When handling a privately defined source description (SDES PRIV)
entry, the length of the private name prefix is taken from the packet
without validating it against the length of the entry. A crafted RTCP SDES packet
can therefore make the processing read beyond the end of the packet buffer.
This affects all versions of gst-plugins-good prior to 1.28.8.
Impact
A malicious third party could trigger an out-of-bounds heap read by having
the application process a crafted RTCP SDES packet, for example by
connecting to a malicious RTSP server or by exchanging RTP/RTCP with an
attacker-controlled peer, for instance via rtspsrc, rtpbin or webrtcbin.
This can result in application crash, denial of service, or information
disclosure of heap memory contents.
Solution
The gst-plugins-good 1.28.8 release addresses the issue. People using older
versions of GStreamer should apply the patch and recompile.
References
The GStreamer project
CVE Database Entries
- No CVE number assigned or pending
GStreamer 1.28.8 release
Patches