What is CVE-2026-19387?
CVE-2026-19387 is a heap out-of-bounds write vulnerability in the GStreamer gst-plugins-bad component, specifically within the adpcmdec element when decoding IMA/DVI ADPCM audio. Insufficient validation of per-block sample counts for multi-channel streams can allow a crafted WAV file to trigger writes beyond the allocated buffer. Users should update gst-plugins-bad to the latest patched version.
Azərbaycanca: CVE-2026-19387 GStreamer-in gst-plugins-bad komponentində aşkarlanmış heap out-of-bounds write zəifliyidir. Bu, xüsusilə adpcmdec elementi vasitəsilə IMA/DVI ADPCM audio fayllarını dekodlaşdırarkən, xüsusi hazırlanmış WAV faylı vasitəsilə çoxkanallı axınlarda bufer hüdudlarını aşmağa imkan verir. İstifadəçilərə gst-plugins-bad paketini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-787
FAQ1
Which component of GStreamer is affected by CVE-2026-19387 and what is the attack vector?
This vulnerability affects the adpcmdec element within the gst-plugins-bad component. A crafted WAV file can trigger a heap out-of-bounds write when decoding IMA/DVI ADPCM audio for multi-channel streams.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.