A flaw was found in GStreamer gst-plugins-good (avidemux). When parsing FUJIFILM metadata in an AVI strd chunk, gst_avi_demux_parse_strd() decrements a remaining-length counter by fixed offsets (98 and 10 bytes) without verifying sufficient data remains. For crafted strd payloads of exactly 106 or 107 bytes, the counter underflows to a very large unsigned value, causing subsequent null-terminated string scanning to read far beyond the allocated heap buffer. Date-format normalization may also write beyond the buffer end. Confirmed impacts include heap out-of-bounds read, out-of-bounds write, heap information disclosure (adjacent data appearing in parsed metadata), and application crash/denial of service. The avidemux element is auto-plugged by playbin, decodebin, and gst-discoverer, so opening or previewing a crafted AVI is sufficient to trigger the issue. Fixed upstream in gst-plugins-good 1.28.6 (GStreamer-SA-2026-0072).
CVSS Details
- CVSS 3.1 Base Score: 6.6
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Redhat_linux | — | Upgrade gstreamer1-plugins-good-debuginfoUpgrade gstreamer1-plugins-goodUpgrade gstreamer1-plugins-good-qt-debuginfoUpgrade gstreamer1-plugins-good-debugsourceNo solution existsUpgrade gstreamer1-plugins-good-gtkUpgrade gstreamer1-plugins-good-gtk-debuginfoUpgrade gstreamer1-plugins-good-qt6-debuginfo | Aug 17, 2026 | Aug 5, 2026 |
| Rocky_linux | — | Upgrade gstreamer1-plugins-good-debuginfoUpgrade gstreamer1-plugins-good-debugsourceUpgrade gstreamer1-plugins-goodUpgrade gstreamer1-plugins-good-gtkUpgrade gstreamer1-plugins-good-gtk-debuginfo | Aug 20, 2026 | Aug 17, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub