Out-of-bounds write in gstreamer - CVE-2026-3086
Published: March 9, 2026 / Updated: May 22, 2026
Vulnerability identifier: #VU123650
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-3086
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error when processing untrusted input within the processing of APS units. A remote attacker can trigger an out-of-bounds write and execute arbitrary code on the target system.
Affected software
gstreamer
Debian Linux
Anolis OS
Fedora
gst-plugins-bad1.0 (Debian package)
mingw-gstreamer1
mingw-gstreamer1-plugins-bad-free
mingw-gstreamer1-plugins-base
mingw-gstreamer1-plugins-good
gstreamer1
gstreamer1-devel
gstreamer1-doc
Debian Linux
Anolis OS
Fedora
gst-plugins-bad1.0 (Debian package)
mingw-gstreamer1
mingw-gstreamer1-plugins-bad-free
mingw-gstreamer1-plugins-base
mingw-gstreamer1-plugins-good
gstreamer1
gstreamer1-devel
gstreamer1-doc
How to mitigate CVE-2026-3086
Install updates from vendor's website.
gstreamer - update to 1.28.1
gst-plugins-bad1.0 (Debian package) - addressed in versions 1.22.0-4+deb12u7, 1.26.2-3+deb13u1
mingw-gstreamer1 - addressed in versions 1.26.11-1.fc42, 1.26.11-1.fc43
mingw-gstreamer1-plugins-bad-free - addressed in versions 1.26.11-1.fc42, 1.26.11-1.fc43
mingw-gstreamer1-plugins-base - addressed in versions 1.26.11-1.fc42, 1.26.11-1.fc43
mingw-gstreamer1-plugins-good - addressed in versions 1.26.11-1.fc42, 1.26.11-1.fc43
gstreamer1 - update to 1.28.1-1
gstreamer1-devel - update to 1.28.1-1
gstreamer1-doc - update to 1.28.1-1
gst-plugins-bad1.0 (Debian package) - addressed in versions 1.22.0-4+deb12u7, 1.26.2-3+deb13u1
mingw-gstreamer1 - addressed in versions 1.26.11-1.fc42, 1.26.11-1.fc43
mingw-gstreamer1-plugins-bad-free - addressed in versions 1.26.11-1.fc42, 1.26.11-1.fc43
mingw-gstreamer1-plugins-base - addressed in versions 1.26.11-1.fc42, 1.26.11-1.fc43
mingw-gstreamer1-plugins-good - addressed in versions 1.26.11-1.fc42, 1.26.11-1.fc43
gstreamer1 - update to 1.28.1-1
gstreamer1-devel - update to 1.28.1-1
gstreamer1-doc - update to 1.28.1-1
External References
Related Security Bulletins
- Multiple vulnerabilities in GStreamer
- Fedora 42 update for mingw-gstreamer1, mingw-gstreamer1-plugins-bad-free, mingw-gstreamer1-plugins-base, mingw-gstreamer1-plugins-good
- Fedora 43 update for mingw-gstreamer1, mingw-gstreamer1-plugins-bad-free, mingw-gstreamer1-plugins-base, mingw-gstreamer1-plugins-good
- Anolis OS update for gstreamer1
- Debian update for gst-plugins-bad1.0