Heap-based Buffer Overflow Vulnerability in GStreamer by Freedesktop
CVE-2026-3082

7.8HIGH

Key Information:

Vendor

Gstreamer

Status
Vendor
CVE Published:
13 March 2026

What is CVE-2026-3082?

This vulnerability within the GStreamer library arises from inadequate validation during the processing of Huffman tables, leading to a heap-based buffer overflow. Attackers can exploit this flaw by supplying specially crafted data, causing arbitrary code execution within the context of the current process. Successful exploitation requires interaction with the affected library, making it critical for users to ensure they are using updated versions to mitigate potential attacks. Reference advisory ZDI-CAN-28840 provides further details.

Affected Version(s)

GStreamer 1c6e163aa33962f5ee4a87d29319ccdd5cb67612

References

CVSS V3.0

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.