Denial of Service Vulnerability in GStreamer's RTP Depayloader Elements
CVE-2026-18649
Key Information:
- Vendor
Red Hat
- Status
- Vendor
- CVE Published:
- 6 August 2026
Badges
What is CVE-2026-18649?
A vulnerability exists in the GStreamer gst-plugins-good package where the rtph264depay and rtph265depay RTP depayloader elements fail to enforce a limit on the size of the reassembly buffer utilized during the processing of fragmented RTP packets. This flaw permits a remote, unauthenticated attacker to exploit the system by sending a continuous stream of RTP fragments without concluding the sequence with an end-of-fragment marker. Consequently, the reassembly buffer can swell indefinitely, ultimately leading to exhaustion of process memory and resulting in a denial of service as the affected process is terminated.
Affected Version(s)
Red Hat Enterprise Linux 10 0:1.26.7-2.el10_2.3
Red Hat Enterprise Linux 8 0:1.16.1-7.el8_10.3
Red Hat Enterprise Linux 9 0:1.22.12-7.el9_8.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved