Back

MEDIUM

Gstreamer1-plugins-good: gstreamer: out-of-bounds read in avidemux vprp video field descriptor parsing

Published Aug 12, 2026

Description

A flaw was found in GStreamer gst-plugins-good (avidemux). In gst_avi_demux_riff_parse_vprp(), the number of available gst_riff_vprp_video_field_desc entries is calculated by dividing the remaining buffer size by the attacker-controlled vprp->fields value, rather than by sizeof(gst_riff_vprp_video_field_desc). This can cause the parser to treat more field descriptors as available than fit in the input buffer, resulting in out-of-bounds reads. Processing a crafted AVI via playbin/decodebin can crash the application (denial of service). Fixed upstream in gst-plugins-good 1.28.6 (GStreamer-SA-2026-0072).

Affected products

Remediation

No remediation recorded yet.

Metrics

References (17)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Aug 12, 2026
Updated Sep 23, 2026
Reserved Aug 12, 2026
CISA Vulnrichment
Updated Aug 13, 2026
NVD
Status Undergoing Analysis
Modified Sep 18, 2026
Red Hat
Severity Moderate
Public date Aug 5, 2026