Gstreamer1-plugins-bad-free: gstreamer: out-of-bounds write in h.266/vvc pps picture partition parser
Published Jun 11, 2026
6.5
MEDIUMCVSS 3.1
EPSS 0.37%
Description
An out-of-bounds write vulnerability was found in GStreamer's H.266/VVC PPS picture partition parser in gst-plugins-bad. In the multi-slice-in-tile processing of gst_h266_parser_parse_picture_partition() (gsth266parser.c), the loop iterates without checking that the slice index stays within bounds, writing past three fixed-size arrays (slice_height_in_ctus, slice_top_left_ctu_x, slice_top_left_ctu_y) in the GstH266PPS structure. While the initial proof-of-concept demonstrated a 4-byte out-of-bounds write, the code permits larger writes across multiple iterations. A crafted H.266/VVC media file can trigger this vulnerability.
Affected products
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | affected |
| |||
| Red Hat | Red Hat Enterprise Linux 7 | affected |
| |||
| Red Hat | Red Hat Enterprise Linux 8 | affected |
| |||
| Red Hat | Red Hat Enterprise Linux 9 | affected |
|
No data.
No data.
Red Hat Enterprise Linux 10
gstreamer1-plugins-bad-free
Fix deferred
Red Hat Enterprise Linux 7
gstreamer1-plugins-bad-free
Fix deferred
Red Hat Enterprise Linux 8
gstreamer1-plugins-bad-free
Fix deferred
Red Hat Enterprise Linux 9
gstreamer1-plugins-bad-free
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | gstreamer1-plugins-bad-free | Fix deferred | n/a |
| Red Hat Enterprise Linux 7 | gstreamer1-plugins-bad-free | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | gstreamer1-plugins-bad-free | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | gstreamer1-plugins-bad-free | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Red Hat statement
The H.266/VVC codec parser is part of gst-plugins-bad and is available in GStreamer 1.26 and later. Older versions of GStreamer shipped in Red Hat Enterprise Linux do not include H.266 support and are not affected. The upstream maintainer confirmed the out-of-bounds write is bounded within preallocated structure arrays and did not cause crashes in testing. Practical exploitation for code execution is considered unlikely with modern hardening such as ASLR and stack protectors.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (5)
- https://access.redhat.com/security/cve/CVE-2026-53701 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2487611 issue-trackingx_refsource_REDHATIssue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-36294 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-53701
- https://www.cve.org/CVERecord?id=CVE-2026-53701
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-53701 | vdb-entryx_refsource_REDHATVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2487611 | issue-trackingx_refsource_REDHATIssue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-36294 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-53701 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-53701 |
Change history (0)
No recorded changes yet.