Security Advisory 2026-0017
|
|
| Summary |
Integer overflow in H.266/VVC parser leading to stack overflow |
| Date |
2026-04-07 |
| Affected Versions |
GStreamer gst-plugins-bad < 1.28.2 |
| IDs |
GStreamer-SA-2026-0017 |
Details
Integer overflow in the H.266/VVC video parser when handling malformed H.266 streams. The overflow occurs during parsing of profile, tier, and level fields, which can lead to a stack-based buffer overflow.
Impact
A malicious third party could trigger a crash in the application, resulting in denial of service, or possibly execute arbitrary code when processing malicious H.266 media files.
Solution
The gst-plugins-bad 1.28.2 release addresses the issue. People using older versions of GStreamer should apply the patch and recompile.
References
The GStreamer project
CVE Database Entries
- No CVE number assigned or pending
GStreamer 1.28.2 release
Patches