WavPack Audio Decoder Vulnerability in GStreamer by Red Hat
CVE-2026-53705
Key Information:
- Vendor
Red Hat
- Status
- Vendor
- CVE Published:
- 15 June 2026
What is CVE-2026-53705?
A vulnerability in GStreamer's WavPack audio decoder, found in gst-plugins-good, allows for heap memory corruption due to an integer overflow during buffer size calculation. This flaw occurs when processing specifically crafted WavPack audio files, leading to inadequate heap allocation. As a result, decoded audio samples can be written beyond the allocated memory space, exposing both 32-bit and 64-bit systems to potential crashes or arbitrary code execution. A remote attacker could exploit this vulnerability by persuading users to open malicious WavPack files.
Affected Version(s)
Red Hat Enterprise Linux 10 0:1.26.7-2.el10_2.1
Red Hat Enterprise Linux 10.0 Extended Update Support 0:1.24.11-1.el10_0.3
Red Hat Enterprise Linux 7 Extended Lifecycle Support 0:1.10.4-4.el7_9.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved