Heap-based Buffer Overflow in GStreamer ASF Demuxer
CVE-2026-2920

7.8HIGH

Key Information:

Vendor

Gstreamer

Status
Vendor
CVE Published:
13 March 2026

What is CVE-2026-2920?

The vulnerability in GStreamer's ASF Demuxer allows remote attackers to execute arbitrary code on affected installations. This security flaw arises from improper validation of user-supplied data length when processing stream headers within ASF files, potentially leading to a buffer overflow in a fixed-length heap-based buffer. By exploiting this weakness, an attacker can execute malicious code within the context of the current process, highlighting the need for vigilance and prompt patching.

Affected Version(s)

GStreamer 1c6e163aa33962f5ee4a87d29319ccdd5cb67612

References

CVSS V3.0

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.