Out-of-Bounds Read Vulnerability in GStreamer by Freedesktop.org
CVE-2026-1940

5.1MEDIUM

What is CVE-2026-1940?

An incomplete fix for a previous vulnerability in GStreamer has led to a scenario where an out-of-bounds read can occur. The fix implemented did not sufficiently account for the correct byte rounding during offset calculations when parsing audio file metadata. This oversight can potentially allow malicious inputs to cause unintended memory access, leading to unpredictable behavior or security risks within applications utilizing the GStreamer framework.

References

CVSS V3.1

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank wooseokdotkim for reporting this issue.
.