Security Advisory 2026-0012
|
|
| Summary |
H.265 video parser potential denial-of-service |
| Date |
2026-02-25 |
| Affected Versions |
GStreamer gst-plugins-bad < 1.28.1 |
| IDs |
GStreamer-SA-2026-0012 |
Details
A missing bounds check in the H.265 video parser could cause a crash for
certain malformed input files through memory exhaustion.
Impact
It is possible for a malicious third party to trigger a crash of the
application through a specially-crafted input file.
Solution
The gst-plugins-bad 1.28.1 release addresses the issue. People using older
versions of GStreamer should apply the patch and recompile.
References
The GStreamer project
CVE Database Entries
GStreamer releases
1.28 (current stable)
Patches