Resource exhaustion in gst-plugins-good and gstreamer - #VU147417
Published: September 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in the RTP session management component when processing incoming RTP packets. A remote attacker can send valid RTP packets containing new source identifiers to exhaust available memory.
The RTP protocol permits up to 15 contributing source identifiers per packet.
Affected software
gstreamer
Remediation
gstreamer - update to 1.28.6