Security Advisory 2026-0007 (CVE-2026-2923, ZDI-CAN-28838)
|
|
| Summary |
Out-of-bounds read and write in DVB Subtitle Decoder |
| Date |
2026-02-25 |
| Affected Versions |
GStreamer gst-plugins-bad < 1.28.1 |
| IDs |
GStreamer-SA-2026-0006 CVE-2026-2923 ZDI-CAN-28838 |
Details
Various out-of-bounds reads and writes in the DVB subtitle decoder that can
cause crashes for certain input files.
Impact
It is possible for a malicious third party to trigger out-of-bounds reads and
writes to heap memory, which can result in a crash of the application.
Solution
The gst-plugins-bad 1.28.1 release addresses the issue. People using older
versions of GStreamer should apply the patch and recompile.
References
The GStreamer project
CVE Database Entries
GStreamer releases
1.28 (current stable)
Patches