Integer overflow in gst-plugins-good and gstreamer - #VU141116

 

Integer overflow in gst-plugins-good and gstreamer - #VU141116

Published: August 6, 2026


Vulnerability identifier: #VU141116
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to integer overflow in the vendored LZO1X decompressor used by the Matroska demuxer when parsing a crafted Matroska or WebM file with LZO1X-compressed data. A remote attacker can provide a specially crafted file to execute arbitrary code.

Merely opening or previewing the crafted file is sufficient to trigger the issue because the Matroska demuxer may be automatically plugged by affected pipelines.


Affected software

gst-plugins-good
gstreamer

Remediation

Install security update from vendor's website.

gst-plugins-good - update to 1.28.5
gstreamer - update to 1.28.5

External References

Related Security Bulletins