Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-18298

Опубликовано: 20 авг. 2026
Источник: redhat
CVSS3: 7.8

Описание

GStreamer PNG File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PNG files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29581.

A flaw was found in GStreamer. This vulnerability, a heap-based buffer overflow during PNG file parsing, allows a remote attacker to execute arbitrary code. Successful exploitation requires user interaction, such as opening a malicious PNG file or visiting a specially crafted web page. The issue arises from inadequate validation of user-supplied data length, which can lead to code execution within the context of the affected process.

Меры по смягчению последствий

To reduce the risk of exploitation, users should avoid opening or processing untrusted PNG files from unknown or suspicious sources. This operational control is crucial as the vulnerability requires user interaction to trigger the heap-based buffer overflow.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6gstreamer-plugins-goodNot affected
Red Hat Enterprise Linux 7gstreamer1-plugins-goodAffected
Red Hat Enterprise Linux 7gstreamer-plugins-goodNot affected
Red Hat Enterprise Linux 8mingw-gstreamer1-plugins-goodAffected
Red Hat Enterprise Linux 10gstreamer1-plugins-goodFixedRHSA-2026:5913324.08.2026
Red Hat Enterprise Linux 8gstreamer1-plugins-goodFixedRHSA-2026:5917924.08.2026
Red Hat Enterprise Linux 9gstreamer1-plugins-goodFixedRHSA-2026:5915224.08.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=2520590gstreamer-plugins-good: GStreamer: Remote code execution via heap-based buffer overflow in PNG file parsing

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 1 месяца назад

GStreamer PNG File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PNG files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29581.

CVSS3: 7.8
nvd
около 1 месяца назад

GStreamer PNG File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PNG files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29581.

CVSS3: 7.8
debian
около 1 месяца назад

GStreamer PNG File Parsing Heap-based Buffer Overflow Remote Code Exec ...

redos
3 дня назад

Уязвимость gstreamer1-plugins-good

redos
3 дня назад

Уязвимость gstreamer1-plugins-good

7.8 High

CVSS3