Heap Out-of-Bounds Read in GStreamer H.264 Video Processing
CVE-2026-12892

4.4MEDIUM

What is CVE-2026-12892?

A vulnerability exists in GStreamer's gst-plugins-bad package where specially crafted H.264 video files can lead to out-of-bounds read access during parsing. This issue arises when the parser fails to verify the sufficiency of data in the NAL unit beyond the extension header before checking slice boundaries. An attacker could exploit this vulnerability by enticing a user into opening a malicious video file, resulting in application crashes or potential leakage of heap memory.

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Ariba Afroz (CoE-CNDS Lab, VJTI, Mumbai, India), Dr. Faruk Kazi (CoE-CNDS Lab, VJTI, Mumbai, India), and Ramesh Adhikari (CoE-CNDS Lab, VJTI, Mumbai, India) for reporting this issue.
.