Heap-based Buffer Overflow in GStreamer Affects Remote Execution Capabilities
CVE-2026-18296

7.8HIGH

Key Information:

Vendor

Gstreamer

Status
Vendor
CVE Published:
20 August 2026

What is CVE-2026-18296?

This vulnerability in the GStreamer Multimedia Framework allows remote attackers to exploit a heap-based buffer overflow during MRF file parsing. The flaw stems from inadequate validation of user-supplied data length before it is copied to a buffer in heap memory. Successful exploitation requires the target user to either visit a malicious webpage or open a specially crafted MRF file. An attacker can leverage this flaw to execute arbitrary code within the context of the affected process, potentially compromising system integrity.

Affected Version(s)

GStreamer 13fcb641ed33d1472e4ffdec2846180b15405053

References

CVSS V3.0

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.