Use-after-free in gstreamer - #VU141083
Published: August 6, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in GstBuffer value deserialization in the GStreamer core library when parsing crafted serialized buffer data with invalid content. A remote attacker can provide specially crafted serialized buffer values to execute arbitrary code.
Successful exploitation may also cause a crash or data corruption.