Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-52722

Опубликовано: 15 июн. 2026
Источник: redhat
CVSS3: 7.1
EPSS Низкий

Описание

A signed integer overflow vulnerability was found in GStreamer's VMnc decoder. A crafted VMnc stream with large cursor dimensions can overflow signed integer payload-size arithmetic, bypassing a length check and leading to out-of-bounds reads. A remote attacker could trick a user into opening a specially crafted VMnc file, potentially causing a crash or information disclosure.

Отчет

This is an Important signed integer overflow vulnerability in the GStreamer VMnc decoder (gst-plugins-bad). The flaw allows out-of-bounds heap reads when processing specially crafted VMnc video files due to signed integer overflow in cursor payload size arithmetic that bypasses a length check. A tiny buffer is allocated based on the overflowed value, but the rendering loop uses the original large dimensions, reading far beyond the allocated memory. The impact affects both availability (crash) and potentially confidentiality (information disclosure from heap memory reads). Red Hat products utilizing GStreamer for multimedia processing are affected if they handle untrusted VMnc video content.

Меры по смягчению последствий

Red Hat is not aware of a practical temporary workaround that fully mitigates this issue or meets Red Hat Product Security's standards for usability, deployment, applicability, or stability. Customers are advised to apply the relevant security updates if they become available.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6gstreamer-plugins-bad-freeOut of support scope
Red Hat Enterprise Linux 7gstreamer-plugins-bad-freeAffected
Red Hat Enterprise Linux 10gstreamer1-plugins-bad-freeFixedRHSA-2026:3674908.07.2026
Red Hat Enterprise Linux 10.0 Extended Update Supportgstreamer1-plugins-bad-freeFixedRHSA-2026:4771729.07.2026
Red Hat Enterprise Linux 7 Extended Lifecycle Supportgstreamer1-plugins-bad-freeFixedRHSA-2026:4717628.07.2026
Red Hat Enterprise Linux 8gstreamer1-plugins-bad-freeFixedRHSA-2026:3713009.07.2026
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Supportgstreamer1-plugins-bad-freeFixedRHSA-2026:4707628.07.2026
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-Ongstreamer1-plugins-bad-freeFixedRHSA-2026:4707628.07.2026
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Supportgstreamer1-plugins-bad-freeFixedRHSA-2026:4707528.07.2026
Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-Ongstreamer1-plugins-bad-freeFixedRHSA-2026:4707528.07.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2486733gstreamer1-plugins-bad-free: GStreamer: Signed integer overflow in VMnc decoder cursor payload handling

EPSS

Процентиль: 32%
0.00392
Низкий

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 7.1
ubuntu
около 2 месяцев назад

A signed integer overflow vulnerability was found in GStreamer's VMnc decoder. A crafted VMnc stream with large cursor dimensions can overflow signed integer payload-size arithmetic, bypassing a length check and leading to out-of-bounds reads. A remote attacker could trick a user into opening a specially crafted VMnc file, potentially causing a crash or information disclosure.

CVSS3: 7.1
nvd
около 2 месяцев назад

A signed integer overflow vulnerability was found in GStreamer's VMnc decoder. A crafted VMnc stream with large cursor dimensions can overflow signed integer payload-size arithmetic, bypassing a length check and leading to out-of-bounds reads. A remote attacker could trick a user into opening a specially crafted VMnc file, potentially causing a crash or information disclosure.

CVSS3: 7.1
debian
около 2 месяцев назад

A signed integer overflow vulnerability was found in GStreamer's VMnc ...

CVSS3: 7.1
github
около 2 месяцев назад

A signed integer overflow vulnerability was found in GStreamer's VMnc decoder. A crafted VMnc stream with large cursor dimensions can overflow signed integer payload-size arithmetic, bypassing a length check and leading to out-of-bounds reads. A remote attacker could trick a user into opening a specially crafted VMnc file, potentially causing a crash or information disclosure.

rocky
21 день назад

Important: gstreamer1-plugins-bad-free security update

EPSS

Процентиль: 32%
0.00392
Низкий

7.1 High

CVSS3