Integer overflow in gst-plugins-bad and gstreamer - #VU141091
Published: August 6, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code or cause a denial of service.
The vulnerability exists due to integer overflow in the H.266/VVC parser when parsing malformed H.266 streams. A remote attacker can trick the victim into opening a crafted H.266 media file to execute arbitrary code or cause a denial of service.
The overflow occurs during parsing of profile, tier, and level fields and can lead to a stack-based buffer overflow.
Affected software
gstreamer
Remediation
gstreamer - update to 1.28.2