Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-52721

Опубликовано: 15 июн. 2026
Источник: debian

Описание

Multiple out-of-bounds read vulnerabilities were found in GStreamer's pcapparse element. Malformed PCAP records can trigger reads beyond buffer boundaries during IPv4/TCP header parsing. This element is primarily used in debugging pipelines, limiting real-world exposure. A local attacker could trick a user into processing a specially crafted PCAP file, potentially leading to a crash or information disclosure.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gst-plugins-bad1.0fixed1.28.5-1package

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=2486732

  • https://gstreamer.freedesktop.org/security/sa-2026-0045.html

  • https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5106 (private)

  • https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/3833dd745ef7b1cd5f699c90897ecca3ef09c59b (1.29.2)

  • https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/7ff8a2811b83f11c48f61a6e5a1d74c912a7f5c4 (1.28.5)

  • Negligible security impact

Связанные уязвимости

CVSS3: 5.3
ubuntu
3 месяца назад

Multiple out-of-bounds read vulnerabilities were found in GStreamer's pcapparse element. Malformed PCAP records can trigger reads beyond buffer boundaries during IPv4/TCP header parsing. This element is primarily used in debugging pipelines, limiting real-world exposure. A local attacker could trick a user into processing a specially crafted PCAP file, potentially leading to a crash or information disclosure.

CVSS3: 5.3
redhat
3 месяца назад

Multiple out-of-bounds read vulnerabilities were found in GStreamer's pcapparse element. Malformed PCAP records can trigger reads beyond buffer boundaries during IPv4/TCP header parsing. This element is primarily used in debugging pipelines, limiting real-world exposure. A local attacker could trick a user into processing a specially crafted PCAP file, potentially leading to a crash or information disclosure.

CVSS3: 5.3
nvd
3 месяца назад

Multiple out-of-bounds read vulnerabilities were found in GStreamer's pcapparse element. Malformed PCAP records can trigger reads beyond buffer boundaries during IPv4/TCP header parsing. This element is primarily used in debugging pipelines, limiting real-world exposure. A local attacker could trick a user into processing a specially crafted PCAP file, potentially leading to a crash or information disclosure.

CVSS3: 5.3
redos
3 дня назад

Уязвимость gstreamer1-plugins-bad-freeworld

CVSS3: 5.3
redos
3 дня назад

Уязвимость gstreamer1-plugins-bad-free