Out-of-bounds read in gst-plugins-good and gstreamer - #VU141138
Published: August 6, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information or cause a denial of service.
The vulnerability exists due to out-of-bounds read in the FLAC stream header parser of the Matroska demuxer when parsing crafted FLAC codec private data from a Matroska or WebM file. A remote attacker can provide a specially crafted file to disclose sensitive information or cause a denial of service.
User interaction is required to open or preview a crafted file.
Affected software
gstreamer
Remediation
gstreamer - update to 1.28.6