Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-19387

Опубликовано: 05 авг. 2026
Источник: redhat
CVSS3: 7.6

Описание

A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio. Insufficient validation of the per-block sample count for multi-channel streams allows a crafted WAV file to cause writes beyond the allocated output buffer. This can lead to application crash, denial of service, memory corruption, or potentially arbitrary code execution when untrusted media is processed.

Отчет

This is an Important flaw in the GStreamer adpcmdec element, which is automatically engaged when processing IMA/DVI ADPCM audio. A specially crafted multi-channel WAV file can trigger a heap out-of-bounds write, leading to application instability, denial of service, or potential code execution. This risk is present in Red Hat environments where applications handle untrusted media, such as in media players or transcoding services.

Меры по смягчению последствий

To mitigate this issue, users should avoid playing or processing untrusted multi-channel IMA ADPCM WAV files. Additionally, consider sandboxing applications that handle untrusted media to limit the potential impact of exploitation.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10gstreamer1-plugins-bad-freeAffected
Red Hat Enterprise Linux 7gstreamer1-plugins-bad-freeAffected
Red Hat Enterprise Linux 8gstreamer1-plugins-bad-freeAffected
Red Hat Enterprise Linux 9gstreamer1-plugins-bad-freeAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2513015gstreamer: gstreamer1-plugins-bad-free: gstreamer: heap out-of-bounds write in adpcmdec IMA/DVI ADPCM decoder

7.6 High

CVSS3

Связанные уязвимости

CVSS3: 7.6
ubuntu
7 дней назад

A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio. Insufficient validation of the per-block sample count for multi-channel streams allows a crafted WAV file to cause writes beyond the allocated output buffer. This can lead to application crash, denial of service, memory corruption, or potentially arbitrary code execution when untrusted media is processed.

CVSS3: 7.6
nvd
7 дней назад

A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio. Insufficient validation of the per-block sample count for multi-channel streams allows a crafted WAV file to cause writes beyond the allocated output buffer. This can lead to application crash, denial of service, memory corruption, or potentially arbitrary code execution when untrusted media is processed.

CVSS3: 7.6
debian
7 дней назад

A heap out-of-bounds write vulnerability was found in the GStreamer gs ...

CVSS3: 7.6
github
7 дней назад

A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio. Insufficient validation of the per-block sample count for multi-channel streams allows a crafted WAV file to cause writes beyond the allocated output buffer. This can lead to application crash, denial of service, memory corruption, or potentially arbitrary code execution when untrusted media is processed.

7.6 High

CVSS3