Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-59692

Опубликовано: 09 июл. 2026
Источник: debian
EPSS Низкий

Описание

A stack buffer overflow vulnerability was found in GStreamer's DTLS plugin. During a DTLS handshake, the peer certificate Subject Distinguished Name is printed into a fixed-size 2048-byte stack buffer without bounds checking. A remote unauthenticated attacker can send a certificate with an oversized Subject DN that exceeds the buffer, causing a stack buffer overflow and process crash, resulting in denial of service.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gst-plugins-bad1.0fixed1.28.5-1package
gst-plugins-bad1.0no-dsatrixiepackage

Примечания

  • https://gstreamer.freedesktop.org/security/sa-2026-0062.html

  • https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12053

  • Fixed by: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/9bb455393b8ccb48e63027f3e30285f80cf3762c (1.28.5)

EPSS

Процентиль: 23%
0.0031
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
22 дня назад

A stack buffer overflow vulnerability was found in GStreamer's DTLS plugin. During a DTLS handshake, the peer certificate Subject Distinguished Name is printed into a fixed-size 2048-byte stack buffer without bounds checking. A remote unauthenticated attacker can send a certificate with an oversized Subject DN that exceeds the buffer, causing a stack buffer overflow and process crash, resulting in denial of service.

CVSS3: 7.5
redhat
24 дня назад

A stack buffer overflow vulnerability was found in GStreamer's DTLS plugin. During a DTLS handshake, the peer certificate Subject Distinguished Name is printed into a fixed-size 2048-byte stack buffer without bounds checking. A remote unauthenticated attacker can send a certificate with an oversized Subject DN that exceeds the buffer, causing a stack buffer overflow and process crash, resulting in denial of service.

CVSS3: 7.5
nvd
22 дня назад

A stack buffer overflow vulnerability was found in GStreamer's DTLS plugin. During a DTLS handshake, the peer certificate Subject Distinguished Name is printed into a fixed-size 2048-byte stack buffer without bounds checking. A remote unauthenticated attacker can send a certificate with an oversized Subject DN that exceeds the buffer, causing a stack buffer overflow and process crash, resulting in denial of service.

CVSS3: 7.5
github
22 дня назад

A stack buffer overflow vulnerability was found in GStreamer's DTLS plugin. During a DTLS handshake, the peer certificate Subject Distinguished Name is printed into a fixed-size 2048-byte stack buffer without bounds checking. A remote unauthenticated attacker can send a certificate with an oversized Subject DN that exceeds the buffer, causing a stack buffer overflow and process crash, resulting in denial of service.

oracle-oval
4 дня назад

ELSA-2026-47180: gstreamer1-plugins-bad-free security update (IMPORTANT)

EPSS

Процентиль: 23%
0.0031
Низкий