Integer overflow in gstreamer - CVE-2026-3084

 

Integer overflow in gstreamer - CVE-2026-3084

Published: March 9, 2026 / Updated: May 22, 2026


Vulnerability identifier: #VU123649
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-3084
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to integer overflow within the parsing of picture partitions. A remote attacker can pass specially crafted data to the application, trigger integer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

gstreamer
Debian Linux
Fedora
gst-plugins-bad1.0 (Debian package)
mingw-gstreamer1
mingw-gstreamer1-plugins-bad-free
mingw-gstreamer1-plugins-base
mingw-gstreamer1-plugins-good

How to mitigate CVE-2026-3084

Install updates from vendor's website.

gstreamer - update to 1.28.1
gst-plugins-bad1.0 (Debian package) - addressed in versions 1.22.0-4+deb12u7, 1.26.2-3+deb13u1
mingw-gstreamer1 - addressed in versions 1.26.11-1.fc42, 1.26.11-1.fc43
mingw-gstreamer1-plugins-bad-free - addressed in versions 1.26.11-1.fc42, 1.26.11-1.fc43
mingw-gstreamer1-plugins-base - addressed in versions 1.26.11-1.fc42, 1.26.11-1.fc43
mingw-gstreamer1-plugins-good - addressed in versions 1.26.11-1.fc42, 1.26.11-1.fc43

External References

Related Security Bulletins