Security Advisory 2026-0004 (CVE-2026-2921, ZDI-CAN-28854)
|
|
| Summary |
Integer overflow in RIFF parser |
| Date |
2026-02-25 |
| Affected Versions |
GStreamer gst-plugins-base < 1.28.1 |
| IDs |
GStreamer-SA-2026-0004 CVE-2026-2921 ZDI-CAN-28854 |
Details
An integer overflow in the RIFF parser that can cause crashes for
certain input files.
Impact
It is possible for a malicious third party to trigger an integer overflow that
can result in out-of-bounds reads and writes to heap memory, and a crash of the
application.
Solution
The gst-plugins-base 1.28.1 release addresses the issue. People using older
versions of GStreamer should apply the patch and recompile.
References
The GStreamer project
CVE Database Entries
GStreamer releases
1.28 (current stable)
Patches