Opened 2 months ago

Closed 7 weeks ago

#23285 closed enhancement (fixed)

gstreamer gst-plugins-base gst-plugins-good gst-plugins-bad gst-plugins-ugly gst-libav gst-plugins-rs-gstreamer 1.28.3

Reported by: Bruce Dubbs Owned by: SecurityAdvisory
Priority: high Milestone: 13.1
Component: BOOK Version: git
Severity: normal Keywords:
Cc:

Description

New point version.

Change History (4)

comment:1 by Douglas R. Reno, 2 months ago

Priority: normalhigh

The GStreamer Security Center reports the following vulnerabilities fixed:

  • GStreamer-SA-2026-0024: Out-of-bounds reads in MPEG PS PES header parsing. "A malicious third party could trigger out-of-bounds reads when processing malicious MPEG Program Stream files, resulting in application crashes and denial of service. Information disclosure is also possible as sensitive memory contents could be exposed."
  • GStreamer-SA-2026-0025: Insufficient validation in MOV/MP4 demuxer uncompressed video handling. "A malicious third party could trigger a crash or denial of service by providing a crafted MOV/MP4 file with invalid uncompressed video parameters."
  • GStreamer-SA-2026-0026: Out-of-bounds write in H.266/VVC parser when parsing PPS tile slices. "A malicious third party could trigger an out-of-bounds write by providing a crafted H.266/VVC video stream with invalid tile slice configuration, potentially resulting in a crash, data corruption, or arbitrary code execution."
  • GStreamer-SA-2026-0027: Out-of-bounds read in MXF demuxer temporal offset check. "A malicious third party could trigger an out-of-bounds read by providing a crafted MXF file with invalid temporal offset values, potentially resulting in a crash or denial of service. Information disclosure is also possible as sensitive memory contents could be exposed."
  • GStreamer-SA-2026-0028: Use-after-free in GStreamer core buffer value deserialization. "A malicious third party could trigger a use-after-free by providing crafted data containing serialized buffer values with invalid content, potentially resulting in a crash, data corruption, or arbitrary code execution."
  • GStreamer-SA-2026-0029: Bounds check errors in MXF VANC packet handling."A malicious third party could trigger out-of-bounds reads or incorrect buffer operations by providing a crafted MXF file with invalid VANC packet configuration, potentially resulting in a crash, data corruption, or denial of service."

Arbitrary code execution and data corruption via any program that uses gstreamer is pretty serious (SA-2026-0028 is in the core gstreamer package itself)

comment:2 by Joe Locash, 2 months ago

Owner: changed from blfs-book to Joe Locash
Status: newassigned

comment:3 by Joe Locash, 2 months ago

Owner: changed from Joe Locash to SecurityAdvisory
Status: assignednew

Release notes: https://gstreamer.freedesktop.org/releases/1.28/#1.28.3

Fixed at d0587f278a. Leaving open for SA.

comment:4 by Douglas R. Reno, 7 weeks ago

Resolution: fixed
Status: newclosed

SA-13.0-091 issued

Note: See TracTickets for help on using tickets.