Stack-based buffer overflow in gstreamer - CVE-2026-3081
Published: March 9, 2026 / Updated: May 22, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error within the parsing of decoding units. A remote unauthenticated attacker can trigger stack-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Debian Linux
Anolis OS
Fedora
gst-plugins-bad1.0 (Debian package)
mingw-gstreamer1
mingw-gstreamer1-plugins-bad-free
mingw-gstreamer1-plugins-base
mingw-gstreamer1-plugins-good
gstreamer1
gstreamer1-devel
gstreamer1-doc
How to mitigate CVE-2026-3081
gst-plugins-bad1.0 (Debian package) - addressed in versions 1.22.0-4+deb12u7, 1.26.2-3+deb13u1
mingw-gstreamer1 - addressed in versions 1.26.11-1.fc42, 1.26.11-1.fc43
mingw-gstreamer1-plugins-bad-free - addressed in versions 1.26.11-1.fc42, 1.26.11-1.fc43
mingw-gstreamer1-plugins-base - addressed in versions 1.26.11-1.fc42, 1.26.11-1.fc43
mingw-gstreamer1-plugins-good - addressed in versions 1.26.11-1.fc42, 1.26.11-1.fc43
gstreamer1 - update to 1.28.1-1
gstreamer1-devel - update to 1.28.1-1
gstreamer1-doc - update to 1.28.1-1
External References
Related Security Bulletins
- Multiple vulnerabilities in GStreamer
- Fedora 42 update for mingw-gstreamer1, mingw-gstreamer1-plugins-bad-free, mingw-gstreamer1-plugins-base, mingw-gstreamer1-plugins-good
- Fedora 43 update for mingw-gstreamer1, mingw-gstreamer1-plugins-bad-free, mingw-gstreamer1-plugins-base, mingw-gstreamer1-plugins-good
- Anolis OS update for gstreamer1
- Debian update for gst-plugins-bad1.0