Integer Overflow Vulnerability in GStreamer ASF Demuxer by Freedesktop.org
CVE-2026-19389
7.1HIGH
What is CVE-2026-19389?
Multiple integer overflow and underflow vulnerabilities were identified in the GStreamer ASF demuxer, affecting its processing of crafted ASF, WMV, or WMA files. This stems from inadequate validation of attacker-controlled length and size inputs, allowing for bounds check circumvention. Successful exploitation can result in out-of-bounds heap reads, potentially leading to application crashes, denial of service scenarios, or limited information disclosure when handling untrusted media.
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Seonwook Kim for reporting this issue.