Denial of Service Vulnerability in GStreamer AV1 Codec Parser by Red Hat
CVE-2026-52718

6.5MEDIUM

What is CVE-2026-52718?

A vulnerability exists in the GStreamer AV1 codec parser that leads to a denial of service. Specifically, the function responsible for parsing tile lists incorrectly handles byte counts instead of bit counts when interfacing with the bit-reader API. This mismanagement can be exploited by a remote attacker, prompting users to open a specially crafted AV1 media file. This exploitation results in assertion aborts and crashes of the application, hindering its normal operation.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank JUNYI LIU for reporting this issue.
.