PT-2024-10365 · Gstreamer+10 · Gstreamer+10
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
GStreamer versions prior to 1.24.10
Description
A null pointer dereference vulnerability has been discovered in the
gst matroska demux parse blockgroup or simpleblock function within matroska-demux.c. This function does not properly check the validity of the *sub pointer of GstBuffer before performing dereferences, which may result in null pointer dereferences. The vulnerability can be exploited by a remote attacker to cause a denial of service.Recommendations
For versions prior to 1.24.10, update to version 1.24.10 to resolve the issue. As a temporary workaround, consider disabling the
gst matroska demux parse blockgroup or simpleblock function until a patch is available. Restrict access to the matroska-demux.c module to minimize the risk of exploitation. Avoid using the GstBuffer *sub pointer in the affected function until the issue is resolved.Exploit
Fix
DoS
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Almalinux
Astra Linux
Debian
Gstreamer
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu