Buffer Overflow Vulnerability in GStreamer Subparse Plugin
CVE-2025-47806

5.6MEDIUM

Key Information:

Vendor

GStreamer

Status
Vendor
CVE Published:
7 August 2025

What is CVE-2025-47806?

In GStreamer, an exploitable buffer overflow vulnerability has been identified in the subparse plugin, specifically within the parse_subrip_time function. This issue allows for data to be written beyond the bounds of a stack buffer, potentially causing application crashes. Users of GStreamer version 1.26.1 and earlier should take immediate precautions to mitigate this risk, as it may open the door to more severe exploitation. For comprehensive security measures and updates, users can refer to the official GStreamer security page.

References

CVSS V3.1

Score:
5.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.