Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-2920

Опубликовано: 13 мар. 2026
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

GStreamer ASF Demuxer Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the processing of stream headers within ASF files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28843.

A flaw was found in GStreamer. This heap-based buffer overflow vulnerability in the ASF Demuxer component allows a remote attacker to execute arbitrary code. The issue arises from insufficient validation of user-supplied data length when processing stream headers within ASF (Advanced Systems Format) files, leading to data being copied to a fixed-length heap-based buffer without proper bounds checking. Successful exploitation can result in arbitrary code execution in the context of the current process.

Отчет

This is an IMPORTANT heap-based buffer overflow vulnerability in the GStreamer ASF Demuxer. The flaw allows remote code execution when processing specially crafted ASF files due to improper validation of stream header lengths. Red Hat products utilizing GStreamer for multimedia processing are affected if they handle untrusted ASF content.

Меры по смягчению последствий

Avoid processing untrusted ASF (Advanced Systems Format) media files. This vulnerability in the GStreamer ASF Demuxer requires user interaction, such as opening a malicious ASF file, to trigger the heap-based buffer overflow. Limiting exposure to untrusted media content can reduce the attack surface.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6gstreamerNot affected
Red Hat Enterprise Linux 7gstreamerNot affected
Red Hat Enterprise Linux 7gstreamer1-plugins-ugly-freeNot affected
Red Hat Enterprise Linux 8gstreamer1-plugins-ugly-freeNot affected
Red Hat Enterprise Linux 10gstreamer1-plugins-bad-freeFixedRHSA-2026:625931.03.2026
Red Hat Enterprise Linux 10gstreamer1-plugins-baseFixedRHSA-2026:625931.03.2026
Red Hat Enterprise Linux 10gstreamer1-plugins-goodFixedRHSA-2026:625931.03.2026
Red Hat Enterprise Linux 10gstreamer1-plugins-ugly-freeFixedRHSA-2026:625931.03.2026
Red Hat Enterprise Linux 10gstreamer1-plugins-bad-freeFixedRHSA-2026:1902419.05.2026
Red Hat Enterprise Linux 10gstreamer1-plugins-baseFixedRHSA-2026:1902419.05.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=2447490gstreamer-plugins-ugly: GStreamer: Arbitrary code execution via ASF file processing

EPSS

Процентиль: 52%
0.00773
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
5 месяцев назад

GStreamer ASF Demuxer Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the processing of stream headers within ASF files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28843.

CVSS3: 7.8
nvd
5 месяцев назад

GStreamer ASF Demuxer Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the processing of stream headers within ASF files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28843.

CVSS3: 7.8
debian
5 месяцев назад

GStreamer ASF Demuxer Heap-based Buffer Overflow Remote Code Execution ...

CVSS3: 7.8
github
5 месяцев назад

GStreamer ASF Demuxer Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the processing of stream headers within ASF files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28843.

CVSS3: 7.8
fstec
6 месяцев назад

Уязвимость плагина ASF мультимедийного фреймворка Gstreamer, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 52%
0.00773
Низкий

7.8 High

CVSS3