Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-52721

Опубликовано: 15 июн. 2026
Источник: redhat
CVSS3: 5.3

Описание

Multiple out-of-bounds read vulnerabilities were found in GStreamer's pcapparse element. Malformed PCAP records can trigger reads beyond buffer boundaries during IPv4/TCP header parsing. This element is primarily used in debugging pipelines, limiting real-world exposure. A local attacker could trick a user into processing a specially crafted PCAP file, potentially leading to a crash or information disclosure.

Отчет

This is a Moderate out-of-bounds read vulnerability in the GStreamer pcapparse element (gst-plugins-bad). The flaw allows reads beyond buffer boundaries when processing malformed PCAP records due to missing bounds validation on IPv4/TCP header fields and untrusted IP packet length values. The impact is limited because the pcapparse element is primarily used in debugging pipelines, not in standard media playback workflows. The upstream maintainer confirmed this can only be triggered in specially crafted GStreamer pipelines built for debugging purposes, making real-world exploitation very unlikely. Red Hat products utilizing GStreamer for multimedia processing are affected only if they use the pcapparse element in custom debugging pipelines.

Меры по смягчению последствий

Red Hat is not aware of a practical temporary workaround that fully mitigates this issue or meets Red Hat Product Security's standards for usability, deployment, applicability, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10gstreamer1-plugins-bad-freeFix deferred
Red Hat Enterprise Linux 6gstreamer-plugins-bad-freeOut of support scope
Red Hat Enterprise Linux 7gstreamer1-plugins-bad-freeFix deferred
Red Hat Enterprise Linux 7gstreamer-plugins-bad-freeFix deferred
Red Hat Enterprise Linux 8gstreamer1-plugins-bad-freeFix deferred
Red Hat Enterprise Linux 9gstreamer1-plugins-bad-freeFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2486732gstreamer1-plugins-bad-free: GStreamer: Multiple out-of-bounds reads in pcapparse IPv4/TCP header parsing

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 2 месяцев назад

Multiple out-of-bounds read vulnerabilities were found in GStreamer's pcapparse element. Malformed PCAP records can trigger reads beyond buffer boundaries during IPv4/TCP header parsing. This element is primarily used in debugging pipelines, limiting real-world exposure. A local attacker could trick a user into processing a specially crafted PCAP file, potentially leading to a crash or information disclosure.

CVSS3: 5.3
nvd
около 2 месяцев назад

Multiple out-of-bounds read vulnerabilities were found in GStreamer's pcapparse element. Malformed PCAP records can trigger reads beyond buffer boundaries during IPv4/TCP header parsing. This element is primarily used in debugging pipelines, limiting real-world exposure. A local attacker could trick a user into processing a specially crafted PCAP file, potentially leading to a crash or information disclosure.

CVSS3: 5.3
debian
около 2 месяцев назад

Multiple out-of-bounds read vulnerabilities were found in GStreamer's ...

CVSS3: 5.3
github
около 2 месяцев назад

Multiple out-of-bounds read vulnerabilities were found in GStreamer's pcapparse element. Malformed PCAP records can trigger reads beyond buffer boundaries during IPv4/TCP header parsing. This element is primarily used in debugging pipelines, limiting real-world exposure. A local attacker could trick a user into processing a specially crafted PCAP file, potentially leading to a crash or information disclosure.

5.3 Medium

CVSS3