PT-2026-51589 · Gstreamer · Gst-Plugins-Bad

·

CVE-2026-12891

·

Published

2026-06-23

·

Updated

2026-07-18

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions GStreamer gst-plugins-bad (affected versions not specified)
Description A flaw in the H.266 parser occurs when processing a malformed H.266/VVC video stream containing a crafted aspect ratio indicator value. This leads to an out-of-bounds read of up to 8 bytes from adjacent memory. An attacker can use a malicious H.266 video file or stream to leak limited memory contents through video metadata, which may expose sensitive information from the application's address space.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12891
ECHO-FE2F-08AD-190B
OPENSUSE-SU-2026:21370-1
SUSE-SU-2026:22752-1
SUSE-SU-2026:22817-1

Affected Products

Gst-Plugins-Bad