Integer overflow in gstreamer - CVE-2026-3084
Published: March 9, 2026 / Updated: May 22, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to integer overflow within the parsing of picture partitions. A remote attacker can pass specially crafted data to the application, trigger integer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Debian Linux
Fedora
gst-plugins-bad1.0 (Debian package)
mingw-gstreamer1
mingw-gstreamer1-plugins-bad-free
mingw-gstreamer1-plugins-base
mingw-gstreamer1-plugins-good
How to mitigate CVE-2026-3084
gst-plugins-bad1.0 (Debian package) - addressed in versions 1.22.0-4+deb12u7, 1.26.2-3+deb13u1
mingw-gstreamer1 - addressed in versions 1.26.11-1.fc42, 1.26.11-1.fc43
mingw-gstreamer1-plugins-bad-free - addressed in versions 1.26.11-1.fc42, 1.26.11-1.fc43
mingw-gstreamer1-plugins-base - addressed in versions 1.26.11-1.fc42, 1.26.11-1.fc43
mingw-gstreamer1-plugins-good - addressed in versions 1.26.11-1.fc42, 1.26.11-1.fc43
External References
Related Security Bulletins
- Multiple vulnerabilities in GStreamer
- Fedora 42 update for mingw-gstreamer1, mingw-gstreamer1-plugins-bad-free, mingw-gstreamer1-plugins-base, mingw-gstreamer1-plugins-good
- Fedora 43 update for mingw-gstreamer1, mingw-gstreamer1-plugins-bad-free, mingw-gstreamer1-plugins-base, mingw-gstreamer1-plugins-good
- Debian update for gst-plugins-bad1.0