GStreamer vulnerabilities
4 CVEs tracked
In our reporting, the GStreamer multimedia framework is under scrutiny due to multiple critical vulnerabilities across its plugin sets (notably gst-plugins-good, gst-plugins-bad, gst-plugins-ugly) that are exploitable through the processing of malformed media files. Key issues include memory corruption flaws triggered by crafted container (Matroska/WebM, ASF/WMV) and audio (FLAC, ADPCM) files, specifically CVE-2026-17072 (heap-based out-of-bounds read), CVE-2026-19389 (integer overflow/underflow), CVE-2026-19387 (heap out-of-bounds write), and CVE-2026-5056 (stack-based buffer overflow) which can lead to remote code execution. Defenders must urgently patch their GStreamer installations and restrict interaction with untrusted media sources.
Azərbaycanca: Hesabatlarımızda GStreamer multimedia framework-ü, onun plugin dəstlərində (xüsusilə gst-plugins-good, gst-plugins-bad, gst-plugins-ugly) aşkarlanmış və istismarı məlumatlı media fayllarının işlənməsi ilə mümkün olan bir neçə kritik zəifliyə görə diqqət mərkəzindədir. Əsas hadisələr sırasına xüsusi hazırlanmış konteyner (Matroska/WebM, ASF/WMV) və audio (FLAC, ADPCM) faylları vasitəsilə yaddaş korrupsiyasına yol açan CVE-2026-17072 (heap-based out-of-bounds read), CVE-2026-19389 (integer overflow/underflow), CVE-2026-19387 (heap out-of-bounds write) və uzaqdan kod icrasına səbəb ola biləcək CVE-2026-5056 (stack-based buffer overflow) daxildir. Müdafiəçilər istifadə olunan GStreamer versiyalarını təcili yeniləməli, şübhəli media mənbələri ilə qarşılıqlı əlaqəni məhdudlaşdırmalıdırlar.
This vendor's CVEs4
This hub is built from skopnix's own reporting on GStreamer: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.