PT-2026-49338 · Gstreamer+1 · Gstreamer+1

·

CVE-2026-52722

·

Published

2026-06-15

·

Updated

2026-08-03

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
Name of the Vulnerable Software and Affected Versions GStreamer (affected versions not specified)
Description A signed integer overflow exists in the VMnc decoder. A specially crafted VMnc stream containing large cursor dimensions can cause an overflow in signed integer payload-size arithmetic. This allows the bypass of a length check, resulting in out-of-bounds reads, which occur when a program reads data past the end of the intended buffer. A remote attacker could exploit this by tricking a user into opening a malicious VMnc file, potentially leading to information disclosure or a system crash.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:36749
ALSA-2026:36834
ALSA-2026:37130
CVE-2026-52722
ECHO-F543-391C-0D44
OPENSUSE-SU-2026:21370-1
SUSE-SU-2026:22752-1
SUSE-SU-2026:22817-1
SUSE-SU-2026:3058-1
SUSE-SU-2026:3125-1
SUSE-SU-2026:3133-1
SUSE-SU-2026:3299-1

Affected Products

Gstreamer
Rocky Linux