Out-Of-Bounds Write Vulnerability in GStreamer by Freedesktop
CVE-2026-3083
8.8HIGH
What is CVE-2026-3083?
The GStreamer library contains a vulnerability that allows remote code execution due to improper validation of user-supplied data in its handling of X-QDM RTP payload elements. When parsing the packetid element, a flaw permits attackers to write beyond the boundaries of allocated memory, resulting in potential execution of arbitrary code in the context of the affected process. Proper interaction with the library is necessary for exploitation, and attack vectors may vary based on specific implementations.
Affected Version(s)
GStreamer 1c6e163aa33962f5ee4a87d29319ccdd5cb67612
