Integer overflow in gst-plugins-good and gstreamer - #VU141116
Published: August 6, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to integer overflow in the vendored LZO1X decompressor used by the Matroska demuxer when parsing a crafted Matroska or WebM file with LZO1X-compressed data. A remote attacker can provide a specially crafted file to execute arbitrary code.
Merely opening or previewing the crafted file is sufficient to trigger the issue because the Matroska demuxer may be automatically plugged by affected pipelines.
Affected software
gstreamer
Remediation
gstreamer - update to 1.28.5