PT-2026-49335 · Gstreamer · Gst-Plugins-Bad

·

CVE-2026-52719

·

Published

2026-06-15

·

Updated

2026-07-08

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
Name of the Vulnerable Software and Affected Versions GStreamer gst-plugins-bad (affected versions not specified)
Description An out-of-bounds read occurs in the VA JPEG decoder within the gst-plugins-bad module. The JPEG parser reads a segment length value from the bitstream without validating it against the available data. A remote attacker can exploit this by inducing a user to open a specially crafted JPEG file, which causes the parsing process to read beyond the input buffer, potentially resulting in a crash or information disclosure.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:36749
ALSA-2026:36834
CVE-2026-52719
ECHO-C6E4-FB80-F88A
OPENSUSE-SU-2026:21204-1
SUSE-SU-2026:2743-1
SUSE-SU-2026:2744-1

Affected Products

Gst-Plugins-Bad