Denial of Service Vulnerability in GStreamer AV1 Codec Parser by Red Hat
CVE-2026-52718
6.5MEDIUM
What is CVE-2026-52718?
A vulnerability exists in the GStreamer AV1 codec parser that leads to a denial of service. Specifically, the function responsible for parsing tile lists incorrectly handles byte counts instead of bit counts when interfacing with the bit-reader API. This mismanagement can be exploited by a remote attacker, prompting users to open a specially crafted AV1 media file. This exploitation results in assertion aborts and crashes of the application, hindering its normal operation.
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank JUNYI LIU for reporting this issue.