Описание
A signed integer overflow vulnerability was found in GStreamer's VMnc decoder. A crafted VMnc stream with large cursor dimensions can overflow signed integer payload-size arithmetic, bypassing a length check and leading to out-of-bounds reads. A remote attacker could trick a user into opening a specially crafted VMnc file, potentially causing a crash or information disclosure.
Отчет
This is an Important signed integer overflow vulnerability in the GStreamer VMnc decoder (gst-plugins-bad). The flaw allows out-of-bounds heap reads when processing specially crafted VMnc video files due to signed integer overflow in cursor payload size arithmetic that bypasses a length check. A tiny buffer is allocated based on the overflowed value, but the rendering loop uses the original large dimensions, reading far beyond the allocated memory. The impact affects both availability (crash) and potentially confidentiality (information disclosure from heap memory reads). Red Hat products utilizing GStreamer for multimedia processing are affected if they handle untrusted VMnc video content.
Меры по смягчению последствий
Red Hat is not aware of a practical temporary workaround that fully mitigates this issue or meets Red Hat Product Security's standards for usability, deployment, applicability, or stability. Customers are advised to apply the relevant security updates if they become available.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | gstreamer-plugins-bad-free | Out of support scope | ||
| Red Hat Enterprise Linux 7 | gstreamer-plugins-bad-free | Affected | ||
| Red Hat Enterprise Linux 10 | gstreamer1-plugins-bad-free | Fixed | RHSA-2026:36749 | 08.07.2026 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | gstreamer1-plugins-bad-free | Fixed | RHSA-2026:47717 | 29.07.2026 |
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | gstreamer1-plugins-bad-free | Fixed | RHSA-2026:47176 | 28.07.2026 |
| Red Hat Enterprise Linux 8 | gstreamer1-plugins-bad-free | Fixed | RHSA-2026:37130 | 09.07.2026 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | gstreamer1-plugins-bad-free | Fixed | RHSA-2026:47076 | 28.07.2026 |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | gstreamer1-plugins-bad-free | Fixed | RHSA-2026:47076 | 28.07.2026 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | gstreamer1-plugins-bad-free | Fixed | RHSA-2026:47075 | 28.07.2026 |
| Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On | gstreamer1-plugins-bad-free | Fixed | RHSA-2026:47075 | 28.07.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.1 High
CVSS3
Связанные уязвимости
A signed integer overflow vulnerability was found in GStreamer's VMnc decoder. A crafted VMnc stream with large cursor dimensions can overflow signed integer payload-size arithmetic, bypassing a length check and leading to out-of-bounds reads. A remote attacker could trick a user into opening a specially crafted VMnc file, potentially causing a crash or information disclosure.
A signed integer overflow vulnerability was found in GStreamer's VMnc decoder. A crafted VMnc stream with large cursor dimensions can overflow signed integer payload-size arithmetic, bypassing a length check and leading to out-of-bounds reads. A remote attacker could trick a user into opening a specially crafted VMnc file, potentially causing a crash or information disclosure.
A signed integer overflow vulnerability was found in GStreamer's VMnc ...
A signed integer overflow vulnerability was found in GStreamer's VMnc decoder. A crafted VMnc stream with large cursor dimensions can overflow signed integer payload-size arithmetic, bypassing a length check and leading to out-of-bounds reads. A remote attacker could trick a user into opening a specially crafted VMnc file, potentially causing a crash or information disclosure.
EPSS
7.1 High
CVSS3