Gstreamer1-plugins-good: gstreamer: out-of-bounds read in avidemux vprp video field descriptor parsing
Published Aug 12, 2026
6.1
MEDIUMCVSS 3.1
EPSS 0.15%
Description
A flaw was found in GStreamer gst-plugins-good (avidemux). In gst_avi_demux_riff_parse_vprp(), the number of available gst_riff_vprp_video_field_desc entries is calculated by dividing the remaining buffer size by the attacker-controlled vprp->fields value, rather than by sizeof(gst_riff_vprp_video_field_desc). This can cause the parser to treat more field descriptors as available than fit in the input buffer, resulting in out-of-bounds reads. Processing a crafted AVI via playbin/decodebin can crash the application (denial of service). Fixed upstream in gst-plugins-good 1.28.6 (GStreamer-SA-2026-0072).
Affected products
-
- Version 0StatusaffectedConstraints<1.28.6
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| GStreamer | Gst-Plugins-Good | unaffected |
|
- < 1.28.6
- 7.0
- 8.0
- 9.0
- 10.0
No data.
Red Hat Enterprise Linux 10
gstreamer1-plugins-good-0:1.26.7-2.el10_2.5
Fixed · RHSA-2026:55434
Red Hat Enterprise Linux 10.0 Extended Update Support
gstreamer1-plugins-good-0:1.24.11-1.el10_0.4
Fixed · RHSA-2026:65959
Red Hat Enterprise Linux 8
gstreamer1-plugins-good-0:1.16.1-7.el8_10.3
Fixed · RHSA-2026:56966
Red Hat Enterprise Linux 8.8 Telecommunications Update Service
gstreamer1-plugins-good-0:1.16.1-5.el8_8.3
Fixed · RHSA-2026:69232
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
gstreamer1-plugins-good-0:1.16.1-5.el8_8.3
Fixed · RHSA-2026:69232
Red Hat Enterprise Linux 9
gstreamer1-plugins-good-0:1.22.12-7.el9_8.4
Fixed · RHSA-2026:55436
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
gstreamer1-plugins-good-0:1.18.4-8.el9_2.3
Fixed · RHSA-2026:68645
Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions
gstreamer1-plugins-good-0:1.22.1-4.el9_4.3
Fixed · RHSA-2026:68642
Red Hat Enterprise Linux 9.6 Extended Update Support
gstreamer1-plugins-good-0:1.22.12-5.el9_6.3
Fixed · RHSA-2026:68644
Red Hat Enterprise Linux 7
gstreamer1-plugins-good
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | gstreamer1-plugins-good-0:1.26.7-2.el10_2.5 | Fixed | RHSA-2026:55434 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | gstreamer1-plugins-good-0:1.24.11-1.el10_0.4 | Fixed | RHSA-2026:65959 |
| Red Hat Enterprise Linux 8 | gstreamer1-plugins-good-0:1.16.1-7.el8_10.3 | Fixed | RHSA-2026:56966 |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | gstreamer1-plugins-good-0:1.16.1-5.el8_8.3 | Fixed | RHSA-2026:69232 |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | gstreamer1-plugins-good-0:1.16.1-5.el8_8.3 | Fixed | RHSA-2026:69232 |
| Red Hat Enterprise Linux 9 | gstreamer1-plugins-good-0:1.22.12-7.el9_8.4 | Fixed | RHSA-2026:55436 |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | gstreamer1-plugins-good-0:1.18.4-8.el9_2.3 | Fixed | RHSA-2026:68645 |
| Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions | gstreamer1-plugins-good-0:1.22.1-4.el9_4.3 | Fixed | RHSA-2026:68642 |
| Red Hat Enterprise Linux 9.6 Extended Update Support | gstreamer1-plugins-good-0:1.22.12-5.el9_6.3 | Fixed | RHSA-2026:68644 |
| Red Hat Enterprise Linux 7 | gstreamer1-plugins-good | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Aug 13, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Aug–Oct 2026- EPSS v5
Percentile over time
- EPSS v5
Table of values (2 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.15% (0.00148) | 3.41th | v5 (v2026.06.15) |
| Aug 13, 2026 | 0.13% (0.00127) | 2.74th | v5 (v2026.06.15) |
References (17)
- https://access.redhat.com/errata/RHSA-2026:55434 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2026:55436 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2026:56966 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:65959 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:68642 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:68644 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:68645 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:69232 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:70264 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:70584 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:70803 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2026-73434 vdb-entryx_refsource_REDHATThird Party AdvisoryVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2514807 issue-trackingx_refsource_REDHATIssue TrackingThird Party Advisory
- https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12231 Issue Tracking
- https://gstreamer.freedesktop.org/security/sa-2026-0072.html PatchVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-73434
- https://www.cve.org/CVERecord?id=CVE-2026-73434
Change history (0)
No recorded changes yet.