Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-53705

Опубликовано: 15 июн. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 7.6

Описание

A flaw was found in GStreamer's WavPack audio decoder in gst-plugins-good. When processing a specially crafted WavPack file, an integer overflow in the buffer size calculation (4 * block_samples * channels) in gst_wavpack_dec_handle_frame() causes a very small heap allocation. The WavPack library then writes decoded audio samples far beyond the allocated buffer, resulting in heap memory corruption. This affects both 32-bit and 64-bit systems since the arithmetic is performed in 32-bit integers before promotion to the allocation size type. A remote attacker could use this flaw to crash an application or potentially execute arbitrary code by convincing a user to open a malicious WavPack audio file.

РелизСтатусПримечание
devel

not-affected

1.28.4-1
esm-infra-legacy/xenial

needs-triage

esm-infra/bionic

needs-triage

esm-infra/focal

needs-triage

jammy

released

1.20.3-0ubuntu1.7
noble

released

1.24.2-1ubuntu1.5
questing

ignored

end of life, was needs-triage
resolute

released

1.28.2-2ubuntu0.1
upstream

released

1.28.4-1

Показывать по

EPSS

Процентиль: 23%
0.0031
Низкий

7.6 High

CVSS3

Связанные уязвимости

CVSS3: 7.6
redhat
около 2 месяцев назад

A flaw was found in GStreamer's WavPack audio decoder in gst-plugins-good. When processing a specially crafted WavPack file, an integer overflow in the buffer size calculation (4 * block_samples * channels) in gst_wavpack_dec_handle_frame() causes a very small heap allocation. The WavPack library then writes decoded audio samples far beyond the allocated buffer, resulting in heap memory corruption. This affects both 32-bit and 64-bit systems since the arithmetic is performed in 32-bit integers before promotion to the allocation size type. A remote attacker could use this flaw to crash an application or potentially execute arbitrary code by convincing a user to open a malicious WavPack audio file.

CVSS3: 7.6
nvd
около 2 месяцев назад

A flaw was found in GStreamer's WavPack audio decoder in gst-plugins-good. When processing a specially crafted WavPack file, an integer overflow in the buffer size calculation (4 * block_samples * channels) in gst_wavpack_dec_handle_frame() causes a very small heap allocation. The WavPack library then writes decoded audio samples far beyond the allocated buffer, resulting in heap memory corruption. This affects both 32-bit and 64-bit systems since the arithmetic is performed in 32-bit integers before promotion to the allocation size type. A remote attacker could use this flaw to crash an application or potentially execute arbitrary code by convincing a user to open a malicious WavPack audio file.

CVSS3: 7.6
debian
около 2 месяцев назад

A flaw was found in GStreamer's WavPack audio decoder in gst-plugins-g ...

suse-cvrf
25 дней назад

Security update for gstreamer-plugins-good

suse-cvrf
21 день назад

Security update for gstreamer-plugins-good

EPSS

Процентиль: 23%
0.0031
Низкий

7.6 High

CVSS3