Out-of-bounds read in gst-plugins-good and gstreamer - CVE-2026-46471
Published: May 22, 2026
gst-plugins-good
gstreamer
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information or cause a denial of service.
The vulnerability exists due to out-of-bounds read in MP4 demuxer when handling specially crafted PlayReady DRM files. A remote attacker can supply a specially crafted file to disclose sensitive information or cause a denial of service.
User interaction is required to process a crafted media file.