Out-of-bounds read in gst-plugins-good and gstreamer - #VU141130
Published: August 6, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in the RTP SBC depayloader element (rtpsbcdepay) when processing crafted RTP packets with no payload data or a minimal payload. A remote attacker can send a specially crafted RTP packet to cause a denial of service.
In builds with assertions disabled, the issue can additionally trigger a use-after-free of a GstBuffer object, but the practical impact remains limited to a crash.
Affected software
gstreamer
Remediation
gstreamer - update to 1.28.5