Описание
An out-of-bounds read vulnerability was found in the VA JPEG decoder in GStreamer's gst-plugins-bad. The JPEG parser reads a segment length value from the bitstream without validating it against available data. A remote attacker could trick a user into opening a specially crafted JPEG file, causing downstream parsing to read beyond the provided input buffer, leading to a crash or potential information disclosure.
Отчет
This is an Important out-of-bounds read vulnerability in the GStreamer VA JPEG decoder (gst-plugins-bad). The flaw allows a crash or potential information disclosure when processing specially crafted JPEG files due to missing bounds validation on the segment length field. The JPEG parser reads an untrusted segment length from the bitstream and downstream callers trust this value without verifying sufficient data is available. The impact affects both availability (crash) and potentially confidentiality (information disclosure from out-of-bounds memory reads). Red Hat products utilizing GStreamer for multimedia processing are affected if they handle untrusted JPEG content through the VA JPEG decoder path.
Меры по смягчению последствий
Red Hat is not aware of a practical temporary workaround that fully mitigates this issue or meets Red Hat Product Security's standards for usability, deployment, applicability, or stability. Customers are advised to apply the relevant security updates if they become available.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | gstreamer-plugins-bad-free | Out of support scope | ||
| Red Hat Enterprise Linux 7 | gstreamer1-plugins-bad-free | Not affected | ||
| Red Hat Enterprise Linux 7 | gstreamer-plugins-bad-free | Not affected | ||
| Red Hat Enterprise Linux 8 | gstreamer1-plugins-bad-free | Not affected | ||
| Red Hat Enterprise Linux 10 | gstreamer1-plugins-bad-free | Fixed | RHSA-2026:36749 | 08.07.2026 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | gstreamer1-plugins-bad-free | Fixed | RHSA-2026:47717 | 29.07.2026 |
| Red Hat Enterprise Linux 9 | gstreamer1-plugins-bad-free | Fixed | RHSA-2026:36834 | 08.07.2026 |
| Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions | gstreamer1-plugins-bad-free | Fixed | RHSA-2026:47071 | 28.07.2026 |
| Red Hat Enterprise Linux 9.6 Extended Update Support | gstreamer1-plugins-bad-free | Fixed | RHSA-2026:47070 | 28.07.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.1 High
CVSS3
Связанные уязвимости
An out-of-bounds read vulnerability was found in the VA JPEG decoder in GStreamer's gst-plugins-bad. The JPEG parser reads a segment length value from the bitstream without validating it against available data. A remote attacker could trick a user into opening a specially crafted JPEG file, causing downstream parsing to read beyond the provided input buffer, leading to a crash or potential information disclosure.
An out-of-bounds read vulnerability was found in the VA JPEG decoder in GStreamer's gst-plugins-bad. The JPEG parser reads a segment length value from the bitstream without validating it against available data. A remote attacker could trick a user into opening a specially crafted JPEG file, causing downstream parsing to read beyond the provided input buffer, leading to a crash or potential information disclosure.
An out-of-bounds read vulnerability was found in the VA JPEG decoder i ...
EPSS
7.1 High
CVSS3