Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-52719

Опубликовано: 15 июн. 2026
Источник: redhat
CVSS3: 7.1
EPSS Низкий

Описание

An out-of-bounds read vulnerability was found in the VA JPEG decoder in GStreamer's gst-plugins-bad. The JPEG parser reads a segment length value from the bitstream without validating it against available data. A remote attacker could trick a user into opening a specially crafted JPEG file, causing downstream parsing to read beyond the provided input buffer, leading to a crash or potential information disclosure.

Отчет

This is an Important out-of-bounds read vulnerability in the GStreamer VA JPEG decoder (gst-plugins-bad). The flaw allows a crash or potential information disclosure when processing specially crafted JPEG files due to missing bounds validation on the segment length field. The JPEG parser reads an untrusted segment length from the bitstream and downstream callers trust this value without verifying sufficient data is available. The impact affects both availability (crash) and potentially confidentiality (information disclosure from out-of-bounds memory reads). Red Hat products utilizing GStreamer for multimedia processing are affected if they handle untrusted JPEG content through the VA JPEG decoder path.

Меры по смягчению последствий

Red Hat is not aware of a practical temporary workaround that fully mitigates this issue or meets Red Hat Product Security's standards for usability, deployment, applicability, or stability. Customers are advised to apply the relevant security updates if they become available.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6gstreamer-plugins-bad-freeOut of support scope
Red Hat Enterprise Linux 7gstreamer1-plugins-bad-freeNot affected
Red Hat Enterprise Linux 7gstreamer-plugins-bad-freeNot affected
Red Hat Enterprise Linux 8gstreamer1-plugins-bad-freeNot affected
Red Hat Enterprise Linux 10gstreamer1-plugins-bad-freeFixedRHSA-2026:3674908.07.2026
Red Hat Enterprise Linux 10.0 Extended Update Supportgstreamer1-plugins-bad-freeFixedRHSA-2026:4771729.07.2026
Red Hat Enterprise Linux 9gstreamer1-plugins-bad-freeFixedRHSA-2026:3683408.07.2026
Red Hat Enterprise Linux 9.4 Update Services for SAP Solutionsgstreamer1-plugins-bad-freeFixedRHSA-2026:4707128.07.2026
Red Hat Enterprise Linux 9.6 Extended Update Supportgstreamer1-plugins-bad-freeFixedRHSA-2026:4707028.07.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2486353gstreamer1-plugins-bad-free: GStreamer: Out-of-bounds read via JPEG segment length validation in VA decoder

EPSS

Процентиль: 27%
0.00341
Низкий

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 7.1
ubuntu
около 2 месяцев назад

An out-of-bounds read vulnerability was found in the VA JPEG decoder in GStreamer's gst-plugins-bad. The JPEG parser reads a segment length value from the bitstream without validating it against available data. A remote attacker could trick a user into opening a specially crafted JPEG file, causing downstream parsing to read beyond the provided input buffer, leading to a crash or potential information disclosure.

CVSS3: 7.1
nvd
около 2 месяцев назад

An out-of-bounds read vulnerability was found in the VA JPEG decoder in GStreamer's gst-plugins-bad. The JPEG parser reads a segment length value from the bitstream without validating it against available data. A remote attacker could trick a user into opening a specially crafted JPEG file, causing downstream parsing to read beyond the provided input buffer, leading to a crash or potential information disclosure.

CVSS3: 7.1
debian
около 2 месяцев назад

An out-of-bounds read vulnerability was found in the VA JPEG decoder i ...

suse-cvrf
29 дней назад

Security update for gstreamer-plugins-bad

suse-cvrf
28 дней назад

Security update for gstreamer-plugins-bad

EPSS

Процентиль: 27%
0.00341
Низкий

7.1 High

CVSS3