Heap-based buffer overflow in gst-plugins-base and gstreamer - #VU141126
Published: August 6, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service or disclose sensitive information.
The vulnerability exists due to a heap-based buffer overflow in the encoding-target loader when parsing malformed UTF-8 input through the public encoding profile API. A local user can provide a specially crafted string containing a truncated UTF-8 sequence to cause a denial of service or disclose sensitive information.
The issue is triggered when the input ends with a truncated multi-byte UTF-8 sequence.
Affected software
gstreamer
Remediation
gstreamer - update to 1.28.5