Denial of Service Vulnerability in GStreamer Audio Processing
CVE-2026-46469

4MEDIUM

Key Information:

Vendor

Gstreamer

Vendor
CVE Published:
14 May 2026

What is CVE-2026-46469?

A vulnerability exists in the GStreamer gst-plugins-good suite, specifically within the isomp4 plugin. The issue arises when parsing MP4 audio tracks; the qtdemux_parse_trak function fails to properly validate atom data during division operations, which may result in a denial of service due to integer division by zero. This could potentially disrupt applications relying on GStreamer for audio processing.

Affected Version(s)

Good Plug-ins 0 < 1.28.2

References

CVSS V3.1

Score:
4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.