Integer Overflow Vulnerability in GStreamer ASF Demuxer by Freedesktop.org
CVE-2026-19389

7.1HIGH

What is CVE-2026-19389?

Multiple integer overflow and underflow vulnerabilities were identified in the GStreamer ASF demuxer, affecting its processing of crafted ASF, WMV, or WMA files. This stems from inadequate validation of attacker-controlled length and size inputs, allowing for bounds check circumvention. Successful exploitation can result in out-of-bounds heap reads, potentially leading to application crashes, denial of service scenarios, or limited information disclosure when handling untrusted media.

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Seonwook Kim for reporting this issue.
.