Out-of-bounds read in gst-plugins-bad and gstreamer - CVE-2026-12891
Published: August 6, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to out-of-bounds read in the H.266/VVC parser when parsing VUI parameters from the sequence parameter set. A local user can provide a crafted H.266/VVC media file with an invalid aspect ratio index to cause a denial of service.
User interaction is required to open or process a crafted media file.
Affected software
gstreamer
How to mitigate CVE-2026-12891
gstreamer - update to 1.28.5