Buffer Overflow in GStreamer OGG File Parsing
CVE-2026-18297

7.8HIGH

Key Information:

Vendor

Gstreamer

Status
Vendor
CVE Published:
20 August 2026

What is CVE-2026-18297?

This vulnerability arises from inadequate validation of user-supplied data length during OGG file parsing in GStreamer, leading to a stack-based buffer overflow. By tricking users into opening crafted files or visiting malicious web pages, attackers could execute arbitrary code within the affected user's context. It highlights the importance of thorough input validation to safeguard against remote code execution risks.

Affected Version(s)

GStreamer e3d33ecb5765f11c85b5ba739a0f1cf2bea81abe

References

CVSS V3.0

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.