Signed Integer Overflow Vulnerability in GStreamer’s VMnc Decoder
CVE-2026-52722
7.1HIGH
Key Information:
- Vendor
Red Hat
- Status
- Vendor
- CVE Published:
- 15 June 2026
What is CVE-2026-52722?
A vulnerability exists in GStreamer's VMnc decoder that involves a signed integer overflow issue. This occurs when processing a specially crafted VMnc stream with excessively large cursor dimensions. The vulnerability can bypass a length check due to payload-size arithmetic overflow, which can lead to out-of-bounds reads. A remote attacker could potentially exploit this by deceiving a user into opening a malicious VMnc file, resulting in a crash or possible information disclosure.
Affected Version(s)
Red Hat Enterprise Linux 10 0:1.26.7-2.el10_2.4
Red Hat Enterprise Linux 10.0 Extended Update Support 0:1.24.11-3.el10_0.4
Red Hat Enterprise Linux 7 Extended Lifecycle Support 0:1.10.4-6.el7_9
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank JUNYI LIU for reporting this issue.