Out-of-bounds read in gst-plugins-ugly and gstreamer - #VU141155
Published: August 6, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to out-of-bounds read in the ASF-over-RTP depayloader element (rtpasfdepay) when processing crafted RTP packets with ASF payload data. A remote attacker can send crafted RTP packets to cause a denial of service.
Optional RTP header fields were read before bounds validation, and ASF packet header fields were parsed without checking that the offset remains within the allocated buffer.
Affected software
gstreamer
Remediation
gstreamer - update to 1.28.5