Bug 2527944

Summary: CVE-2026-85150 mingw-gstreamer1-plugins-base: gstreamer: NULL/invalid-pointer dereference in gst_rtsp_message_parse_auth_credentials() when parsing a crafted Digest Authorization/WWW-Authenticate header [fedora-all]
Product: [Fedora] Fedora Reporter: lcelant
Component: mingw-gstreamer1-plugins-baseAssignee: Sandro Mani <manisandro>
Status: CLOSED ERRATA QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: medium Docs Contact:
Priority: medium    
Version: rawhideCC: manisandro, tuxator
Target Milestone: ---Keywords: Security, SecurityTracking
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard: {"flaws": ["69facc18-a874-4a83-9ba2-4c4e6722289f"]}
Fixed In Version: mingw-gstreamer1-plugins-base-1.28.7-1.fc45 mingw-gstreamer1-plugins-base-1.28.7-1.fc44 Doc Type: ---
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2026-09-27 00:29:15 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 2527936    

Description lcelant 2026-09-03 10:47:01 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

gst-plugins-base's RTSP support library (subprojects/gst-plugins-base/gst-libs/gst/rtsp/gstrtspmessage.c) implements gst_rtsp_message_parse_auth_credentials(), used by both gst-rtsp-server (to parse a client's Authorization header, gst-rtsp-server/gst/rtsp-server/rtsp-auth.c:861, default_authenticate()) and by RTSP clients such as gstrtspsrc (gst-plugins-good/gst/rtsp/gstrtspsrc.c:6966) and rtspclientsink (gst-rtsp-sink/gstrtspclientsink.c:2737) to parse a server's WWW-Authenticate header. The internal helper parse_auth_credentials() (gstrtspmessage.c, static function, ~line 1362) tokenizes comma-separated auth-param name=value pairs. For each parameter it computes `item_end = skip_item(header)` (the end of the current token, which points AT the whitespace/comma/NUL character that terminated the token, not past it), then does `value = skip_lws(eq + 1); auth_param->value = g_strndup(value, item_end - value);` (line ~1421-1425). skip_lws() has no awareness of item_end: if the character skip_item() used as the token terminator happens to be whitespace, skip_lws() will step over it (and any further whitespace) looking for a non-space character, potentially advancing `value` past `item_end`. This makes `item_end - value` a negative ptrdiff_t, which is implicitly converted to gsize (an unsigned 64-bit value near G_MAXSIZE) when passed to g_strndup(). Because n+1 (computed inside g_strndup) wraps to 0 on the -1 case, g_new(gchar, 0) resolves to g_malloc(0), which by GLib's documented contract returns NULL; strncpy() is then invoked with this NULL destination and n=G_MAXSIZE, corrupting/crashing, and even where g_strndup does return, the resulting NULL is stored into auth_param->value without a NULL check. Immediately afterward the code does `if (value[0] == '"') decode_quoted_string(auth_param->value);` -- value[0] here is checked on the original (non-NULL) source pointer, so the branch can be taken even though auth_param->value is NULL, and decode_quoted_string() dereferences the NULL pointer, causing SIGSEGV. Reporter (Roy Lau, royworking98) reported this to the GStreamer security contacts on 2026-08-26 (gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5278), and the maintainers merged a fix at gitlab.freedesktop.org/gstreamer/gstreamer-security/-/merge_requests/120 on 2026-09-02, targeting the 1.28.7 release. Reporter tested against gstreamer <= 1.28.2; the vulnerable code path is present up to (and reportedly including) versions prior to 1.28.7. Verified independently via static source review against the 1.28.2 tag; dynamic PoC execution was not performed. PSIRT Ticket: PSIRTSUPT-23042 (GST-SA-2026-0082).

Comment 1 Fedora Update System 2026-09-18 22:08:42 UTC
FEDORA-2026-d5e9ea2b8c (mingw-gstreamer1-1.28.7-1.fc44, mingw-gstreamer1-plugins-bad-free-1.28.7-1.fc44, and 2 more) has been submitted as an update to Fedora 44.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-d5e9ea2b8c

Comment 2 Fedora Update System 2026-09-18 22:09:10 UTC
FEDORA-2026-0d2736f2fe (mingw-gstreamer1-1.28.7-1.fc45, mingw-gstreamer1-plugins-bad-free-1.28.7-1.fc45, and 2 more) has been submitted as an update to Fedora 45.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-0d2736f2fe

Comment 3 Fedora Update System 2026-09-19 01:40:44 UTC
FEDORA-2026-0d2736f2fe has been pushed to the Fedora 45 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-0d2736f2fe`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2026-0d2736f2fe

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 4 Fedora Update System 2026-09-19 02:19:37 UTC
FEDORA-2026-d5e9ea2b8c has been pushed to the Fedora 44 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-d5e9ea2b8c`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2026-d5e9ea2b8c

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 5 Fedora Update System 2026-09-27 00:29:15 UTC
FEDORA-2026-0d2736f2fe (mingw-gstreamer1-1.28.7-1.fc45, mingw-gstreamer1-plugins-bad-free-1.28.7-1.fc45, and 2 more) has been pushed to the Fedora 45 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 6 Fedora Update System 2026-09-27 00:57:32 UTC
FEDORA-2026-d5e9ea2b8c (mingw-gstreamer1-1.28.7-1.fc44, mingw-gstreamer1-plugins-bad-free-1.28.7-1.fc44, and 2 more) has been pushed to the Fedora 44 stable repository.
If problem still persists, please make note of it in this bug report.