Integer overflow in gst-plugins-good and gstreamer - CVE-2026-39044
Published: May 22, 2026
gst-plugins-good
gstreamer
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to integer overflow in the WAV parser (wavparse) when parsing malformed WAV files with cue chunks. A remote attacker can trick the victim into opening a crafted WAV file to cause a denial of service.
Memory exhaustion may also occur during cue chunk parsing.