GStreamer
open source multimedia framework

GStreamer Conference 2026

10-11 October 2026 ยท Prague, Czech Republic

Join us!
Home
Features
News
Annual Conference
Planet (Blogs)
Download
Applications
Security Center
GitLab
Developers
Documentation
Forum
File a Bug
Artwork
Follow us on Bluesky
Follow us on Mastodon
Chat with us on Matrix

Security Advisory 2026-0091

Summary Out-of-bounds read in RTCP SDES privately defined entry handling
Date 2026-10-08
Affected Versions GStreamer gst-plugins-good < 1.28.8
IDs GStreamer-SA-2026-0091

Details

An out-of-bounds read vulnerability in the RTP session handling of gst-plugins-good, which processes incoming RTCP (RTP Control Protocol) packets. When handling a privately defined source description (SDES PRIV) entry, the length of the private name prefix is taken from the packet without validating it against the length of the entry. A crafted RTCP SDES packet can therefore make the processing read beyond the end of the packet buffer.

This affects all versions of gst-plugins-good prior to 1.28.8.

Impact

A malicious third party could trigger an out-of-bounds heap read by having the application process a crafted RTCP SDES packet, for example by connecting to a malicious RTSP server or by exchanging RTP/RTCP with an attacker-controlled peer, for instance via rtspsrc, rtpbin or webrtcbin. This can result in application crash, denial of service, or information disclosure of heap memory contents.

Solution

The gst-plugins-good 1.28.8 release addresses the issue. People using older versions of GStreamer should apply the patch and recompile.

References

The GStreamer project

CVE Database Entries

  • No CVE number assigned or pending

GStreamer 1.28.8 release

Patches


Report a problem on this page.