PT-2026-71265 · Gstreamer+1 · Gst-Plugins-Good+1

CVE-2026-73433

·

Published

2026-08-12

·

Updated

2026-08-20

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions gst-plugins-good versions prior to 1.28.6
Description A flaw exists in the avidemux element when parsing FUJIFILM metadata within an AVI strd chunk. The function gst avi demux parse strd() decrements a remaining-length counter by fixed offsets of 98 and 10 bytes without verifying if sufficient data remains. If a crafted strd payload is exactly 106 or 107 bytes, the counter underflows to a large unsigned value, leading to null-terminated string scanning that reads far beyond the allocated heap buffer. Additionally, date-format normalization may result in writing beyond the buffer end. This can lead to heap out-of-bounds read, out-of-bounds write, heap information disclosure where adjacent data appears in parsed metadata, and application crashes or denial of service. The issue can be triggered by opening or previewing a crafted AVI file, as the avidemux element is auto-plugged by playbin, decodebin, and gst-discoverer.
Recommendations Update gst-plugins-good to version 1.28.6.

Exploit

Fix

DoS

Integer Underflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:55434
ALSA-2026:55436
ALSA-2026:56966
CVE-2026-73433
ECHO-0929-81EA-1686
OESA-2026-3481
OESA-2026-3484
RHSA-2026:55434
RHSA-2026:55436

Affected Products

Rocky Linux
Gst-Plugins-Good