Stack-based buffer overflow in gstreamer - CVE-2026-3081

 

Stack-based buffer overflow in gstreamer - CVE-2026-3081

Published: March 9, 2026 / Updated: May 22, 2026


Vulnerability identifier: #VU123642
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-3081
CWE-ID: CWE-121
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error within the parsing of decoding units. A remote unauthenticated attacker can trigger stack-based buffer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

gstreamer
Debian Linux
Anolis OS
Fedora
gst-plugins-bad1.0 (Debian package)
mingw-gstreamer1
mingw-gstreamer1-plugins-bad-free
mingw-gstreamer1-plugins-base
mingw-gstreamer1-plugins-good
gstreamer1
gstreamer1-devel
gstreamer1-doc

How to mitigate CVE-2026-3081

Install updates from vendor's website.

gstreamer - update to 1.28.1
gst-plugins-bad1.0 (Debian package) - addressed in versions 1.22.0-4+deb12u7, 1.26.2-3+deb13u1
mingw-gstreamer1 - addressed in versions 1.26.11-1.fc42, 1.26.11-1.fc43
mingw-gstreamer1-plugins-bad-free - addressed in versions 1.26.11-1.fc42, 1.26.11-1.fc43
mingw-gstreamer1-plugins-base - addressed in versions 1.26.11-1.fc42, 1.26.11-1.fc43
mingw-gstreamer1-plugins-good - addressed in versions 1.26.11-1.fc42, 1.26.11-1.fc43
gstreamer1 - update to 1.28.1-1
gstreamer1-devel - update to 1.28.1-1
gstreamer1-doc - update to 1.28.1-1

External References

Related Security Bulletins