Stack-based buffer overflow in gst-plugins-base and gstreamer - #VU141127
Published: August 6, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code or cause a denial of service.
The vulnerability exists due to stack-based buffer overflow in the Opus audio decoder when processing crafted Opus streams with more than 64 channels. A remote attacker can supply a specially crafted Opus stream to execute arbitrary code or cause a denial of service.
The issue is triggered because the decoder uses the channel count from the stream header for memory operations on fixed-size 64-element arrays.
Affected software
gstreamer
Remediation
gstreamer - update to 1.28.5