Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd parsing leading to out-of-bounds read/write
Published Aug 12, 2026
6.6
MEDIUMCVSS 3.1
EPSS 0.15%
Description
A flaw was found in GStreamer gst-plugins-good (avidemux). When parsing FUJIFILM metadata in an AVI strd chunk, gst_avi_demux_parse_strd() decrements a remaining-length counter by fixed offsets (98 and 10 bytes) without verifying sufficient data remains. For crafted strd payloads of exactly 106 or 107 bytes, the counter underflows to a very large unsigned value, causing subsequent null-terminated string scanning to read far beyond the allocated heap buffer. Date-format normalization may also write beyond the buffer end. Confirmed impacts include heap out-of-bounds read, out-of-bounds write, heap information disclosure (adjacent data appearing in parsed metadata), and application crash/denial of service. The avidemux element is auto-plugged by playbin, decodebin, and gst-discoverer, so opening or previewing a crafted AVI is sufficient to trigger the issue. Fixed upstream in gst-plugins-good 1.28.6 (GStreamer-SA-2026-0072).
Affected products
-
- Version 0StatusaffectedConstraints<1.28.6
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| GStreamer | Gst-Plugins-Good | unaffected |
|
- ≤ 1.28.6
- 7.0
- 8.0
- 9.0
- 10.0
No data.
Red Hat Enterprise Linux 10
gstreamer1-plugins-good-0:1.26.7-2.el10_2.5
Fixed · RHSA-2026:55434
Red Hat Enterprise Linux 10.0 Extended Update Support
gstreamer1-plugins-good-0:1.24.11-1.el10_0.4
Fixed · RHSA-2026:65959
Red Hat Enterprise Linux 8
gstreamer1-plugins-good-0:1.16.1-7.el8_10.3
Fixed · RHSA-2026:56966
Red Hat Enterprise Linux 8.8 Telecommunications Update Service
gstreamer1-plugins-good-0:1.16.1-5.el8_8.3
Fixed · RHSA-2026:69232
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
gstreamer1-plugins-good-0:1.16.1-5.el8_8.3
Fixed · RHSA-2026:69232
Red Hat Enterprise Linux 9
gstreamer1-plugins-good-0:1.22.12-7.el9_8.4
Fixed · RHSA-2026:55436
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
gstreamer1-plugins-good-0:1.18.4-8.el9_2.3
Fixed · RHSA-2026:68645
Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions
gstreamer1-plugins-good-0:1.22.1-4.el9_4.3
Fixed · RHSA-2026:68642
Red Hat Enterprise Linux 9.6 Extended Update Support
gstreamer1-plugins-good-0:1.22.12-5.el9_6.3
Fixed · RHSA-2026:68644
Red Hat Enterprise Linux 7
gstreamer1-plugins-good
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | gstreamer1-plugins-good-0:1.26.7-2.el10_2.5 | Fixed | RHSA-2026:55434 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | gstreamer1-plugins-good-0:1.24.11-1.el10_0.4 | Fixed | RHSA-2026:65959 |
| Red Hat Enterprise Linux 8 | gstreamer1-plugins-good-0:1.16.1-7.el8_10.3 | Fixed | RHSA-2026:56966 |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | gstreamer1-plugins-good-0:1.16.1-5.el8_8.3 | Fixed | RHSA-2026:69232 |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | gstreamer1-plugins-good-0:1.16.1-5.el8_8.3 | Fixed | RHSA-2026:69232 |
| Red Hat Enterprise Linux 9 | gstreamer1-plugins-good-0:1.22.12-7.el9_8.4 | Fixed | RHSA-2026:55436 |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | gstreamer1-plugins-good-0:1.18.4-8.el9_2.3 | Fixed | RHSA-2026:68645 |
| Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions | gstreamer1-plugins-good-0:1.22.1-4.el9_4.3 | Fixed | RHSA-2026:68642 |
| Red Hat Enterprise Linux 9.6 Extended Update Support | gstreamer1-plugins-good-0:1.22.12-5.el9_6.3 | Fixed | RHSA-2026:68644 |
| Red Hat Enterprise Linux 7 | gstreamer1-plugins-good | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Aug 14, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Aug–Oct 2026- EPSS v5
Percentile over time
- EPSS v5
Table of values (2 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.15% (0.00148) | 3.41th | v5 (v2026.06.15) |
| Aug 13, 2026 | 0.13% (0.00127) | 2.74th | v5 (v2026.06.15) |
References (17)
- https://access.redhat.com/errata/RHSA-2026:55434 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2026:55436 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2026:56966 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:65959 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:68642 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:68644 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:68645 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:69232 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:70264 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:70584 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:70803 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2026-73433 vdb-entryx_refsource_REDHATThird Party AdvisoryVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2514801 issue-trackingx_refsource_REDHATIssue TrackingThird Party Advisory
- https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12231 Issue Tracking
- https://gstreamer.freedesktop.org/security/sa-2026-0072.html PatchVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-73433
- https://www.cve.org/CVERecord?id=CVE-2026-73433
Change history (0)
No recorded changes yet.