Bug 2447503 (CVE-2026-2923)
| Summary: | CVE-2026-2923 GStreamer: GStreamer: Remote Code Execution via out-of-bounds write in DVB Subtitles handling | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | Keywords: | Security |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in GStreamer. This out-of-bounds write vulnerability in the DVB (Digital Video Broadcasting) Subtitles handling allows remote attackers to execute arbitrary code. The issue stems from improper validation of user-supplied coordinate data, which can lead to writing beyond the boundaries of an allocated memory buffer. Successful exploitation can result in arbitrary code execution within the context of the current process.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2448016, 2447998, 2448002, 2448021, 2448025 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-03-13 21:02:48 UTC
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:6259 https://access.redhat.com/errata/RHSA-2026:6259 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:6300 https://access.redhat.com/errata/RHSA-2026:6300 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:6750 https://access.redhat.com/errata/RHSA-2026:6750 This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:8854 https://access.redhat.com/errata/RHSA-2026:8854 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:8862 https://access.redhat.com/errata/RHSA-2026:8862 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:19024 https://access.redhat.com/errata/RHSA-2026:19024 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:19180 https://access.redhat.com/errata/RHSA-2026:19180 |