Back

MEDIUM

Gstreamer1-plugins-bad-free: gstreamer: out-of-bounds write in h.266/vvc pps picture partition parser

Published Jun 11, 2026

Description

An out-of-bounds write vulnerability was found in GStreamer's H.266/VVC PPS picture partition parser in gst-plugins-bad. In the multi-slice-in-tile processing of gst_h266_parser_parse_picture_partition() (gsth266parser.c), the loop iterates without checking that the slice index stays within bounds, writing past three fixed-size arrays (slice_height_in_ctus, slice_top_left_ctu_x, slice_top_left_ctu_y) in the GstH266PPS structure. While the initial proof-of-concept demonstrated a 4-byte out-of-bounds write, the code permits larger writes across multiple iterations. A crafted H.266/VVC media file can trigger this vulnerability.

Affected products

Remediation

Vendor solution

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Red Hat statement

The H.266/VVC codec parser is part of gst-plugins-bad and is available in GStreamer 1.26 and later. Older versions of GStreamer shipped in Red Hat Enterprise Linux do not include H.266 support and are not affected. The upstream maintainer confirmed the out-of-bounds write is bounded within preallocated structure arrays and did not cause crashes in testing. Practical exploitation for code execution is considered unlikely with modern hardening such as ASLR and stack protectors.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jun 11, 2026
Updated Jun 15, 2026
Reserved Jun 10, 2026
CISA Vulnrichment
Updated Jun 11, 2026
NVD
Status Awaiting Analysis
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jun 10, 2026
ENISA EUVD
Assigner redhat
Published Jun 11, 2026
Updated Jun 15, 2026
Exploited since n/a
EUVD-2026-36294