Fedora Account System
Red Hat Associate
Red Hat Customer
GStreamer gst-plugins-good contains a vulnerability in the MOV/MP4 demuxer (qtdemux) closed-caption parser. In the extract_cc_from_data() function in subprojects/gst-plugins-good/gst/isomp4/qtdemux.c, when parsing a CEA-608 caption sample containing two atoms (cdat/cdt2), the bounds check for the second atom at line 6426 computes 'atom_length + new_atom_length' using 32-bit unsigned arithmetic (both are guint32). An attacker can craft the second atom's length (new_atom_length) such that this addition wraps around to a small value, bypassing the bounds check. The value 'new_atom_length - 8' is then passed to convert_to_s334_1a() as a guint8 parameter (ccpair_size), truncating a large 32-bit value to at most 244 bytes. This causes convert_to_s334_1a() to read up to 244 bytes beyond the valid caption sample buffer, and the out-of-bounds heap data is included in the downstream caption output stream. Versions prior to gst-plugins-good 1.28.7 are affected. Fixed in gst-plugins-good 1.28.7. Security Advisory: GStreamer-SA-2026-0079. Upstream MR: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12433. Reported by Seonwook Kim. PSIRT ticket: PSIRTSUPT-23503.