Gstreamer · Gst-Plugins-Bad · CVE-2026-12891
**Name of the Vulnerable Software and Affected Versions**
GStreamer gst-plugins-bad (affected versions not specified)
**Description**
A flaw in the H.266 parser occurs when processing a malformed H.266/VVC video stream containing a crafted aspect ratio indicator value. This leads to an out-of-bounds read of up to 8 bytes from adjacent memory. An attacker can use a malicious H.266 video file or stream to leak limited memory contents through video metadata, which may expose sensitive information from the application's address space.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.