PT-2026-49341 · Gstreamer+3 · Gstreamer+4

·

CVE-2026-53705

·

Published

2026-06-12

·

Updated

2026-08-31

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions GStreamer (affected versions not specified)
Description A flaw exists in the WavPack audio decoder within gst-plugins-good. An integer overflow occurs during the buffer size calculation (4 * block samples * channels) inside the gst wavpack dec handle frame() function when processing a specially crafted WavPack file. This results in an undersized heap allocation, allowing the WavPack library to write decoded audio samples beyond the allocated buffer, leading to heap memory corruption. This issue impacts both 32-bit and 64-bit systems because the arithmetic is performed using 32-bit integers before being promoted to the allocation size type. A remote attacker could exploit this to crash an application or potentially execute arbitrary code if a user is convinced to open a malicious WavPack audio file.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:36675
ALSA-2026:36774
ALSA-2026:37129
CVE-2026-53705
ECHO-E662-10E6-6EB5
OESA-2026-3481
OESA-2026-3482
OESA-2026-3483
OESA-2026-3484
OESA-2026-3485
OPENSUSE-SU-2026:21240-1
RHSA-2026:36675
RHSA-2026:36774
RHSA-2026:37129
RHSA-2026:47032
RHSA-2026:47050
RHSA-2026:47051
RHSA-2026:47052
RHSA-2026:47174
RHSA-2026:49602
RHSA-2026:49603
RHSA-2026:49604
SUSE-SU-2026:2727-1
SUSE-SU-2026:2842-1
SUSE-SU-2026:2843-1
SUSE-SU-2026:2844-1
USN-8584-1

Affected Products

Gstreamer
Linuxmint
Rocky Linux
Ubuntu
Gst-Plugins-Good