Out-of-bounds read in gst-plugins-bad and gstreamer - CVE-2026-53701
Published: August 6, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information or cause a denial of service.
The vulnerability exists due to an out-of-bounds read in the H.266/VVC codec parser (gsth266parser) when parsing Picture Parameter Set (PPS) tile slices. A remote attacker can provide a crafted H.266/VVC video stream with a large picture dimension and an excessive number of explicitly signalled slices per tile to disclose sensitive information or cause a denial of service.
Affected software
gstreamer
Debian Linux
Anolis OS
gst-plugins-bad1.0 (Debian package)
gstreamer1-plugins-bad-free
gstreamer1-plugins-bad-free-devel
gstreamer1-plugins-bad-free-libs
gstreamer1-plugins-bad-free-doc
How to mitigate CVE-2026-53701
gstreamer - update to 1.28.5
gst-plugins-bad1.0 (Debian package) - update to 1.26.2-3+deb13u2
gstreamer1-plugins-bad-free - update to 1.28.1-4
gstreamer1-plugins-bad-free-devel - update to 1.28.1-4
gstreamer1-plugins-bad-free-libs - update to 1.28.1-4
gstreamer1-plugins-bad-free-doc - update to 1.28.1-4