A flaw was found in GStreamer gst-plugins-good (avidemux). In gst_avi_demux_riff_parse_vprp(), the number of available gst_riff_vprp_video_field_desc entries is calculated by dividing the remaining buffer size by the attacker-controlled vprp->fields value, rather than by sizeof(gst_riff_vprp_video_field_desc). This can cause the parser to treat more field descriptors as available than fit in the input buffer, resulting in out-of-bounds reads. Processing a crafted AVI via playbin/decodebin can crash the application (denial of service). Fixed upstream in gst-plugins-good 1.28.6 (GStreamer-SA-2026-0072).
CVSS Details
- CVSS 3.1 Base Score: 6.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Redhat_linux | — | Upgrade gstreamer1-plugins-good-qt6-debuginfoNo solution existsUpgrade gstreamer1-plugins-good-gtkUpgrade gstreamer1-plugins-good-debuginfoUpgrade gstreamer1-plugins-good-qt-debuginfoUpgrade gstreamer1-plugins-good-gtk-debuginfoUpgrade gstreamer1-plugins-good-debugsourceUpgrade gstreamer1-plugins-good | Aug 17, 2026 | Aug 5, 2026 |
| Rocky_linux | — | Upgrade gstreamer1-plugins-good-debuginfoUpgrade gstreamer1-plugins-good-gtkUpgrade gstreamer1-plugins-good-debugsourceUpgrade gstreamer1-plugins-goodUpgrade gstreamer1-plugins-good-gtk-debuginfo | Aug 20, 2026 | Aug 17, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub