Security Advisory 2026-0002 (CVE-2026-46471)
|
|
| Summary |
Out-of-bounds read in MP4 demuxer |
| Date |
2026-02-25 |
| Affected Versions |
GStreamer gst-plugins-good < 1.28.1 |
| IDs |
GStreamer-SA-2026-0002 CVE-2026-46471 |
Details
An out-of-bounds read in the MP4 demuxer on handling specially crafted PlayReady
DRM files, which can cause crashes or information leaks.
Impact
It is possible for a malicious third party to trigger an out-of-bounds read
that can result in a crash of the application or information leaks.
Solution
The gst-plugins-bad 1.28.1 release addresses the issue. People using older
versions of GStreamer should apply the patch and recompile.
References
The GStreamer project
CVE Database Entries
GStreamer releases
1.28 (current stable)
Patches