WavPack Audio Decoder Vulnerability in GStreamer by Red Hat
CVE-2026-53705

7.6HIGH

What is CVE-2026-53705?

A vulnerability in GStreamer's WavPack audio decoder, found in gst-plugins-good, allows for heap memory corruption due to an integer overflow during buffer size calculation. This flaw occurs when processing specifically crafted WavPack audio files, leading to inadequate heap allocation. As a result, decoded audio samples can be written beyond the allocated memory space, exposing both 32-bit and 64-bit systems to potential crashes or arbitrary code execution. A remote attacker could exploit this vulnerability by persuading users to open malicious WavPack files.

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Seung Min Shin for reporting this issue.
.