What is CVE-2026-19389?
CVE-2026-19389 refers to multiple integer overflow and underflow vulnerabilities in the GStreamer gst-plugins-ugly ASF demuxer when processing crafted ASF, WMV, or WMA files. These flaws can lead to out-of-bounds writes due to insufficient validation of attacker-controlled values. Affected users should apply security patches immediately.
Azərbaycanca: CVE-2026-19389 GStreamer-in gst-plugins-ugly paketindəki ASF demuxer-də aşkar edilmiş çoxsaylı integer overflow/underflow zəiflikləridir. Bu zəiflik xüsusi hazırlanmış ASF, WMV və ya WMA fayllarını emal edərkən baş verir və yaddaş kənarına yazma (out-of-bounds write) ilə nəticələnə bilər. Təsirə məruz qalan sistemlərin dərhal təhlükəsizlik yeniləmələrini tətbiq etmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-190
FAQ2
In which GStreamer component was CVE-2026-19389 discovered?
CVE-2026-19389 was discovered in the ASF demuxer within GStreamer's gst-plugins-ugly package.
Which file types can trigger an out-of-bounds write via CVE-2026-19389?
Specially crafted ASF, WMV, or WMA files can trigger an out-of-bounds write due to integer overflow or underflow.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.