Out-of-bounds write in gst-libav and gstreamer - #VU147413
Published: September 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to out-of-bounds read and write operations in the FFmpeg audio decoder and encoder elements in gst-libav when processing a crafted media file with more than 64 audio channels. A remote attacker can supply a crafted media file with more than 64 audio channels to cause a denial of service.
Affected software
gstreamer
Remediation
gstreamer - update to 1.28.7