A flaw was found in GStreamer's RealMedia demuxer in the gst-plugins-ugly package. When processing a RealMedia file containing a specially crafted FILEINFO metadata section, the demuxer parses variable-name and variable-value pairs using re_skip_pascal_string() without validating that offsets remain within the mapped buffer. Additionally, the element count controlling the parsing loop is read from attacker-controlled data without validation, which can cause an infinite loop. A crafted RealMedia file can cause the application to crash, hang, or potentially read limited adjacent memory contents.
CVSS Details
- CVSS 3.1 Base Score: 7.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade gstreamer1-plugins-ugly-free | Jul 9, 2026 | Jul 8, 2026 |
| Freebsd | — | Upgrade gstreamer1-plugins-uglyUpgrade gstreamer1-plugins-goodUpgrade gstreamer1-libavUpgrade gstreamer1-pluginsUpgrade gstreamer1-plugins-bad | Jun 30, 2026 | Jun 29, 2026 |
| Redhat_linux | — | Upgrade gstreamer1-plugins-ugly-freeUpgrade gstreamer1-plugins-ugly-free-debuginfoUpgrade gstreamer1-plugins-ugly-free-debugsource | Jul 10, 2026 | Jun 12, 2026 |
| Rocky_linux | — | Upgrade gstreamer1-plugins-ugly-freeUpgrade gstreamer1-plugins-ugly-free-debuginfoUpgrade gstreamer1-plugins-ugly-free-debugsource | Jul 13, 2026 | Jul 10, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub