Описание
A denial of service vulnerability was found in GStreamer's AV1 codec parser in gst-plugins-bad. The gst_av1_parser_parse_tile_list_obu() function passes a byte count to a bit-reader API that expects a bit count, causing parser desynchronization. A remote attacker could trick a user into opening a specially crafted AV1 media file, triggering an assertion abort and causing the application to crash.
Отчет
This is a Moderate denial of service vulnerability in the GStreamer AV1 codec parser (gst-plugins-bad). The flaw allows a deterministic application crash when processing specially crafted AV1 media files due to a byte/bit unit confusion in gst_av1_parser_parse_tile_list_obu(). The impact is limited to availability since the assertion abort terminates the process immediately with no path to code execution or information disclosure. Red Hat products utilizing GStreamer for multimedia processing are affected if they handle untrusted AV1 media content.
Меры по смягчению последствий
Red Hat is not aware of a practical temporary workaround that fully mitigates this issue or meets Red Hat Product Security's standards for usability, deployment, applicability, or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | gstreamer-plugins-bad-free | Out of support scope | ||
| Red Hat Enterprise Linux 7 | gstreamer1-plugins-bad-free | Not affected | ||
| Red Hat Enterprise Linux 7 | gstreamer-plugins-bad-free | Not affected | ||
| Red Hat Enterprise Linux 8 | gstreamer1-plugins-bad-free | Not affected | ||
| Red Hat Enterprise Linux 10 | gstreamer1-plugins-bad-free | Fixed | RHSA-2026:36749 | 08.07.2026 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | gstreamer1-plugins-bad-free | Fixed | RHSA-2026:47717 | 29.07.2026 |
| Red Hat Enterprise Linux 9 | gstreamer1-plugins-bad-free | Fixed | RHSA-2026:36834 | 08.07.2026 |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | gstreamer1-plugins-bad-free | Fixed | RHSA-2026:47069 | 28.07.2026 |
| Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions | gstreamer1-plugins-bad-free | Fixed | RHSA-2026:47071 | 28.07.2026 |
| Red Hat Enterprise Linux 9.6 Extended Update Support | gstreamer1-plugins-bad-free | Fixed | RHSA-2026:47070 | 28.07.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
A denial of service vulnerability was found in GStreamer's AV1 codec parser in gst-plugins-bad. The gst_av1_parser_parse_tile_list_obu() function passes a byte count to a bit-reader API that expects a bit count, causing parser desynchronization. A remote attacker could trick a user into opening a specially crafted AV1 media file, triggering an assertion abort and causing the application to crash.
A denial of service vulnerability was found in GStreamer's AV1 codec parser in gst-plugins-bad. The gst_av1_parser_parse_tile_list_obu() function passes a byte count to a bit-reader API that expects a bit count, causing parser desynchronization. A remote attacker could trick a user into opening a specially crafted AV1 media file, triggering an assertion abort and causing the application to crash.
A denial of service vulnerability was found in GStreamer's AV1 codec p ...
A denial of service vulnerability was found in GStreamer's AV1 codec parser in gst-plugins-bad. The gst_av1_parser_parse_tile_list_obu() function passes a byte count to a bit-reader API that expects a bit count, causing parser desynchronization. A remote attacker could trick a user into opening a specially crafted AV1 media file, triggering an assertion abort and causing the application to crash.
EPSS
6.5 Medium
CVSS3