Bug 2531416 (CVE-2026-88914) - CVE-2026-88914 gstreamer1-plugins-good: gstreamer: integer overflow and out-of-bounds read in qtdemux CEA-608 closed-caption parser
Summary: CVE-2026-88914 gstreamer1-plugins-good: gstreamer: integer overflow and out-o...
Keywords:
Status: NEW
Alias: CVE-2026-88914
Deadline: 2026-10-30
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-10 13:00 UTC by OSIDB Bzimport
Modified: 2026-09-10 14:59 UTC (History)
3 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-10 13:00:03 UTC
GStreamer gst-plugins-good contains a vulnerability in the MOV/MP4 demuxer (qtdemux) closed-caption parser. In the extract_cc_from_data() function in subprojects/gst-plugins-good/gst/isomp4/qtdemux.c, when parsing a CEA-608 caption sample containing two atoms (cdat/cdt2), the bounds check for the second atom at line 6426 computes 'atom_length + new_atom_length' using 32-bit unsigned arithmetic (both are guint32). An attacker can craft the second atom's length (new_atom_length) such that this addition wraps around to a small value, bypassing the bounds check. The value 'new_atom_length - 8' is then passed to convert_to_s334_1a() as a guint8 parameter (ccpair_size), truncating a large 32-bit value to at most 244 bytes. This causes convert_to_s334_1a() to read up to 244 bytes beyond the valid caption sample buffer, and the out-of-bounds heap data is included in the downstream caption output stream. Versions prior to gst-plugins-good 1.28.7 are affected. Fixed in gst-plugins-good 1.28.7. Security Advisory: GStreamer-SA-2026-0079. Upstream MR: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12433. Reported by Seonwook Kim. PSIRT ticket: PSIRTSUPT-23503.


Note You need to log in before you can comment on or make changes to this bug.