Rapid7

vulnerability

Red Hat: CVE-2024-0444: gstreamer: AV1 Video Parsing Stack-based Buffer Overflow (Multiple Advisories)

Severity
8
CVSS
(AV:N/AC:H/Au:N/C:C/I:C/A:C)
Published
Jun 7, 2024
Added
May 14, 2025
Modified
Jun 12, 2026

Description

A stack-based buffer overflow flaw was found in GStreamer. This issue may lead to code execution while parsing tile list data within AV1-encoded video files.

Solutions

redhat-upgrade-gstreamer1redhat-upgrade-gstreamer1-debuginforedhat-upgrade-gstreamer1-debugsourceredhat-upgrade-gstreamer1-develredhat-upgrade-gstreamer1-plugins-bad-freeredhat-upgrade-gstreamer1-plugins-bad-free-debuginforedhat-upgrade-gstreamer1-plugins-bad-free-debugsourceredhat-upgrade-gstreamer1-plugins-bad-free-develredhat-upgrade-gstreamer1-plugins-bad-free-libsredhat-upgrade-gstreamer1-plugins-bad-free-libs-debuginforedhat-upgrade-gstreamer1-plugins-ugly-freeredhat-upgrade-gstreamer1-plugins-ugly-free-debuginforedhat-upgrade-gstreamer1-plugins-ugly-free-debugsourceredhat-upgrade-gstreamer1-rtsp-serverredhat-upgrade-gstreamer1-rtsp-server-debuginforedhat-upgrade-gstreamer1-rtsp-server-debugsourceredhat-upgrade-gstreamer1-rtsp-server-devel-debuginfo
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.