Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-18649

Опубликовано: 06 авг. 2026
Источник: debian

Описание

A flaw was found in the GStreamer gst-plugins-good package. The rtph264depay and rtph265depay RTP depayloader elements do not enforce a maximum size limit on the reassembly buffer used during fragmented RTP packet processing. A remote, unauthenticated attacker can send a continuous stream of RTP fragments without ever transmitting an end-of-fragment marker, causing the reassembly buffer to grow without bound until process memory is exhausted. This results in a denial of service through process termination.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gst-plugins-good1.0fixed1.28.6-1package

Примечания

  • https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12234

  • https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12244

  • Fixed by: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/5cd490c125e04676659593b0f5b19130fc2face7 (1.28.6)

  • Fixed by: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/820bd15585b13af8be9b0131699655194ae68a5b (1.28.6)

  • https://gstreamer.freedesktop.org/security/sa-2026-0076.html

Связанные уязвимости

CVSS3: 7.5
ubuntu
11 дней назад

A flaw was found in the GStreamer gst-plugins-good package. The rtph264depay and rtph265depay RTP depayloader elements do not enforce a maximum size limit on the reassembly buffer used during fragmented RTP packet processing. A remote, unauthenticated attacker can send a continuous stream of RTP fragments without ever transmitting an end-of-fragment marker, causing the reassembly buffer to grow without bound until process memory is exhausted. This results in a denial of service through process termination.

CVSS3: 7.5
redhat
11 дней назад

A flaw was found in the GStreamer gst-plugins-good package. The rtph264depay and rtph265depay RTP depayloader elements do not enforce a maximum size limit on the reassembly buffer used during fragmented RTP packet processing. A remote, unauthenticated attacker can send a continuous stream of RTP fragments without ever transmitting an end-of-fragment marker, causing the reassembly buffer to grow without bound until process memory is exhausted. This results in a denial of service through process termination.

CVSS3: 7.5
nvd
11 дней назад

A flaw was found in the GStreamer gst-plugins-good package. The rtph264depay and rtph265depay RTP depayloader elements do not enforce a maximum size limit on the reassembly buffer used during fragmented RTP packet processing. A remote, unauthenticated attacker can send a continuous stream of RTP fragments without ever transmitting an end-of-fragment marker, causing the reassembly buffer to grow without bound until process memory is exhausted. This results in a denial of service through process termination.

rocky
5 дней назад

Moderate: gstreamer1-plugins-good security update

rocky
5 дней назад

Moderate: gstreamer1-plugins-good security update