Integer overflow in gst-plugins-ugly and gstreamer - #VU141154
Published: August 6, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to integer overflow in the ASF-over-RTP depayloader element (rtpasfdepay) when processing crafted RTP packets with ASF payload data. A remote attacker can send crafted RTP packets to cause a denial of service.
The issue occurs when the reassembled ASF chunk size exceeds the negotiated maximum packet size, leading to an unsigned arithmetic underflow and a very large value being passed to memset.
Affected software
gstreamer
Remediation
gstreamer - update to 1.28.5