Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-18649

Опубликовано: 06 авг. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A flaw was found in the GStreamer gst-plugins-good package. The rtph264depay and rtph265depay RTP depayloader elements do not enforce a maximum size limit on the reassembly buffer used during fragmented RTP packet processing. A remote, unauthenticated attacker can send a continuous stream of RTP fragments without ever transmitting an end-of-fragment marker, causing the reassembly buffer to grow without bound until process memory is exhausted. This results in a denial of service through process termination.

Отчет

The gstreamer1-plugins-good package ships the rtph264depay and rtph265depay elements in multiple products including Fedora and RHEL. The vulnerability is exploitable when these depayloaders process RTP from untrusted sources without an authentication layer. In deployments using SRTP (via srtpdec) or DTLS-SRTP (via WebRTC/webrtcbin), unauthenticated packets are rejected before reaching the depayloaders, which significantly reduces the attack surface. However, pipelines receiving raw unauthenticated RTP over UDP (e.g. udpsrc directly feeding rtph264depay) are fully exposed. The practical impact depends on whether the deployment uses authenticated RTP transport. Desktop media playback from local files is not affected.

Меры по смягчению последствий

The following mitigations can reduce risk before a patch is available:

  1. Use SRTP or DTLS-SRTP: Deploy the srtpdec element in the pipeline before the depayloader. SRTP provides per-packet authentication and will reject unauthenticated fragments before they reach rtph264depay/rtph265depay, completely preventing exploitation.
  2. Network-level restriction: Use firewall rules (iptables/nftables) to restrict which sources can send RTP traffic to the GStreamer process. Allow RTP only from trusted, authenticated peers.
  3. Build-time exclusion: Disable the entire RTP plugin by configuring with "-Drtp=disabled" in meson build options. This removes all RTP functionality including the vulnerable depayloaders.
  4. Runtime element exclusion: Prevent the affected elements from being auto-plugged by setting GST_PLUGIN_FEATURE_RANK=rtph264depay:0,rtph265depay:0. This prevents automatic selection but not explicit pipeline construction.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7gstreamer1-plugins-goodAffected
Red Hat Enterprise Linux 8gstreamer1-plugins-goodAffected
Red Hat Enterprise Linux 10gstreamer1-plugins-goodFixedRHSA-2026:5345111.08.2026
Red Hat Enterprise Linux 9gstreamer1-plugins-goodFixedRHSA-2026:5345211.08.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2510614gst-plugins-good: gst-plugins-good: unbounded memory growth in rtph264depay and rtph265depay RTP depayloaders

EPSS

Процентиль: 44%
0.00562
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
11 дней назад

A flaw was found in the GStreamer gst-plugins-good package. The rtph264depay and rtph265depay RTP depayloader elements do not enforce a maximum size limit on the reassembly buffer used during fragmented RTP packet processing. A remote, unauthenticated attacker can send a continuous stream of RTP fragments without ever transmitting an end-of-fragment marker, causing the reassembly buffer to grow without bound until process memory is exhausted. This results in a denial of service through process termination.

CVSS3: 7.5
nvd
11 дней назад

A flaw was found in the GStreamer gst-plugins-good package. The rtph264depay and rtph265depay RTP depayloader elements do not enforce a maximum size limit on the reassembly buffer used during fragmented RTP packet processing. A remote, unauthenticated attacker can send a continuous stream of RTP fragments without ever transmitting an end-of-fragment marker, causing the reassembly buffer to grow without bound until process memory is exhausted. This results in a denial of service through process termination.

CVSS3: 7.5
debian
11 дней назад

A flaw was found in the GStreamer gst-plugins-good package. The rtph26 ...

rocky
5 дней назад

Moderate: gstreamer1-plugins-good security update

rocky
5 дней назад

Moderate: gstreamer1-plugins-good security update

EPSS

Процентиль: 44%
0.00562
Низкий

7.5 High

CVSS3