Integer Overflow Vulnerability in GStreamer ASF Demuxer by Freedesktop.org
CVE-2026-19389
7.1HIGH
Key Information:
- Vendor
Red Hat
- Status
- Vendor
- CVE Published:
- 10 August 2026
What is CVE-2026-19389?
Multiple integer overflow and underflow vulnerabilities were identified in the GStreamer ASF demuxer, affecting its processing of crafted ASF, WMV, or WMA files. This stems from inadequate validation of attacker-controlled length and size inputs, allowing for bounds check circumvention. Successful exploitation can result in out-of-bounds heap reads, potentially leading to application crashes, denial of service scenarios, or limited information disclosure when handling untrusted media.
Affected Version(s)
Red Hat Enterprise Linux 10 0:1.26.7-2.el10_2.2
Red Hat Enterprise Linux 10.0 Extended Update Support 0:1.24.11-1.el10_0.3
Red Hat Enterprise Linux 9 0:1.22.12-7.el9_8.4
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Seonwook Kim for reporting this issue.