Rapid7

vulnerability

Red Hat: CVE-2025-3887: gstreamer1-plugins-bad-free: mingw-gstreamer1-plugins-bad-free: GStreamer H265 Codec Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability (Multiple Advisories)

Severity
9
CVSS
(AV:N/AC:M/Au:N/C:C/I:C/A:C)
Published
May 22, 2025
Added
May 28, 2025
Modified
Jun 12, 2026

Description

A flaw was found in GStreamer H265 Codec Parsing (gstreamer1-plugins-bad-free). This vulnerability allows remote attackers to execute arbitrary code by parsing H265 slice headers.

Solutions

redhat-upgrade-gstreamer1-plugins-bad-freeredhat-upgrade-gstreamer1-plugins-bad-free-debuginforedhat-upgrade-gstreamer1-plugins-bad-free-debugsourceredhat-upgrade-gstreamer1-plugins-bad-free-develredhat-upgrade-gstreamer1-plugins-bad-free-libsredhat-upgrade-gstreamer1-plugins-bad-free-libs-debuginfo
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.