A flaw was found in GStreamer's gst-plugins-bad package. When processing a specially crafted H.264 video file containing malformed MVC or SVC extension slice NAL units, a 1-byte heap out-of-bounds read can occur during parsing. This happens when the parser attempts to check slice boundary information without first verifying that the NAL unit contains enough data beyond the extension header. An attacker could exploit this by tricking a user into opening a malicious H.264 video file, potentially causing the application to crash or leak a single byte of heap memory.
CVSS Details
- CVSS 3.1 Base Score: 4.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade gstreamer1-plugins-bad-free-debuginfoUpgrade gstreamer1-plugins-bad-freeUpgrade gstreamer1-plugins-bad-free-devel | Aug 5, 2026 | Aug 5, 2026 |
| Amazon_linux_2023 | — | Upgrade gstreamer1-plugins-bad-free-debugsourceUpgrade gstreamer1-plugins-bad-free-develUpgrade gstreamer1-plugin-openh264-debuginfoUpgrade gstreamer1-plugins-bad-freeUpgrade gstreamer1-plugin-openh264Upgrade gstreamer1-plugins-bad-free-libsUpgrade gstreamer1-plugins-bad-free-debuginfoUpgrade gstreamer1-plugins-bad-free-libs-debuginfo | Aug 10, 2026 | Jun 23, 2026 |
| Debian | — | Upgrade gst-plugins-bad1.0 | Aug 23, 2026 | Aug 23, 2026 |
| Freebsd | — | Upgrade gstreamer1-plugins-badUpgrade gstreamer1-plugins-goodUpgrade gstreamer1-plugins-uglyUpgrade gstreamer1-pluginsUpgrade gstreamer1-libav | Jun 30, 2026 | Jun 29, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Jun 22, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub