Out-Of-Bounds Write Vulnerability in GStreamer by Freedesktop
CVE-2026-2922

7.8HIGH

Key Information:

Vendor

Gstreamer

Status
Vendor
CVE Published:
13 March 2026

What is CVE-2026-2922?

A vulnerability within the GStreamer RealMedia Demuxer allows remote code execution due to improper validation of user-supplied data during video packet processing. This flaw can lead to an attacker executing arbitrary code in the context of the current process. Exploitation requires interaction with the GStreamer library, with potential attack vectors that vary by implementation. Users of GStreamer should be aware of this risk and ensure they update to the patched versions to safeguard against such vulnerabilities.

Affected Version(s)

GStreamer 1c6e163aa33962f5ee4a87d29319ccdd5cb67612

References

CVSS V3.0

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.