A stack buffer overflow flaw was found in the GStreamer H.265 codec parser library (gst-plugins-bad). When parsing a buffering period SEI message, the parser uses an incorrect loop bound derived from cpb_cnt_minus1[i] (the loop index) instead of the sub-layer 0 CPB count cpb_cnt_minus1[0] from the referenced Sequence Parameter Set. A crafted H.265 video file or stream can cause the parser to write beyond the bounds of stack-allocated CPB delay arrays, resulting in a crash or potential stack memory corruption.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade gstreamer1-plugins-bad-free-develUpgrade gstreamer1-plugins-bad-free-debuginfoUpgrade gstreamer1-plugin-openh264-debuginfoUpgrade gstreamer1-plugins-bad-free-debugsourceUpgrade gstreamer1-plugins-bad-free-libs-debuginfoUpgrade gstreamer1-plugin-openh264Upgrade gstreamer1-plugins-bad-free-libsUpgrade gstreamer1-plugins-bad-free | Jul 8, 2026 | Jun 11, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Jun 10, 2026 |
| Ubuntu | — | Upgrade gstreamer1.0-plugins-badUpgrade libgstreamer-plugins-bad1.0-0 | Jun 17, 2026 | Jun 11, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jul 6, 2026 | Jun 11, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub