Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-12893

Опубликовано: 12 июн. 2026
Источник: redhat
CVSS3: 5.5

Описание

A flaw was found in the GStreamer gst-libav plugin. A NULL pointer dereference in the demuxer error handler can be triggered when processing malformed media files, such as crafted Musepack (.mpc) files. When a user or application opens such a file using GStreamer, the application crashes, resulting in a denial of service.

Отчет

This flaw affects Red Hat Enterprise Linux versions that ship gstreamer1-libav packages. The impact is limited to denial of service (application crash) when processing maliciously crafted media files. Modern operating systems with NULL page protection prevent this from being exploited for code execution. The vulnerability requires local access to a malformed media file and user interaction to trigger. Applications using GStreamer to process untrusted media files (media players, video editors, thumbnail generators, file indexers) are affected. Network-facing services that automatically process uploaded media may also be impacted, but this requires the attacker to upload a malformed file and depends on service configuration.

Меры по смягчению последствий

Avoid opening untrusted media files from unknown sources until the package is updated. Organizations can implement application allowlisting to restrict which applications can process media files, or use sandboxing technologies (SELinux, AppArmor, containers) to limit the impact of crashes in media processing applications.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=2491322gstreamer1-libav: gstreamer1-libav: NULL pointer dereference in gstavdemux.c error handler

5.5 Medium

CVSS3

Связанные уязвимости

ubuntu
около 1 месяца назад

[gstreamer1-libav: gstreamer1-libav: NULL pointer dereference in gstavdemux.c error handler]

debian

[gstreamer1-libav: gstreamer1-libav: NULL pointer dereference in gstavdemux.c error handler]

5.5 Medium

CVSS3