PT-2026-49334 · Gstreamer+1 · Gstreamer+2

·

CVE-2026-52718

·

Published

2026-06-15

·

Updated

2026-08-24

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions GStreamer (affected versions not specified)
Description A denial of service issue exists in the AV1 codec parser within gst-plugins-bad. The gst av1 parser parse tile list obu() function incorrectly passes a byte count to a bit-reader API that expects a bit count, leading to parser desynchronization. A remote attacker can cause the application to crash via an assertion abort by tricking a user into opening a specially crafted AV1 media file.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Assertion Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:36749
ALSA-2026:36834
CVE-2026-52718
ECHO-DAAE-39E9-F2C0
OPENSUSE-SU-2026:11088-1
OPENSUSE-SU-2026:21629-1
RHSA-2026:36749
RHSA-2026:36834
RHSA-2026:47069
RHSA-2026:47070
RHSA-2026:47071
RHSA-2026:47717
SUSE-SU-2026:23274-1
SUSE-SU-2026:23308-1
SUSE-SU-2026:3527-1

Affected Products

Gstreamer
Rocky Linux
Gst-Plugins-Bad