Bug 2506750 (CVE-2026-17072) - CVE-2026-17072 gstreamer1-plugins-good: gst-plugins-good: 4-byte heap over-read in gst_matroska_parse_flac_stream_headers when parsing FLAC codec data in Matroska containers
Summary: CVE-2026-17072 gstreamer1-plugins-good: gst-plugins-good: 4-byte heap over-re...
Keywords:
Status: NEW
Alias: CVE-2026-17072
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-24 14:13 UTC by OSIDB Bzimport
Modified: 2026-07-28 11:09 UTC (History)
3 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-07-24 14:13:36 UTC
A 4-byte heap-buffer-overflow (out-of-bounds read) was found in gst-plugins-good's Matroska demuxer, in the function gst_matroska_parse_flac_stream_headers() in gst/matroska/matroska-ids.c. When parsing FLAC codec private data embedded in a Matroska (MKV/WebM) container, the function iterates over FLAC metadata blocks. Each block has a 4-byte header (1 byte flags + 3 bytes length) followed by a body of 'len' bytes. The bounds check at line 309 validates 'off + len > codec_data_size' but the subsequent gst_buffer_new_memdup() at line 314 copies 'len + 4' bytes (body + header). When off + len == codec_data_size, the guard passes but the memdup reads 4 bytes past the end of the heap-allocated codec_data buffer. The correct check should be 'off + 4 + len > codec_data_size'. This function is called from matroska-demux.c line 7397 when processing A_FLAC audio tracks.

Affected versions: <= 1.28.5
Fixed in version: 1.28.6 (upcoming)
Fix MR: https://gitlab.freedesktop.org/gstreamer/gstreamer-security/-/merge_requests/111 (GST-SA-2026-0073)
Reporter: Yazan Balawneh, CyStack Security Team
ASan confirmation on GStreamer 1.28.4, Kali Linux x86_64: heap-buffer-overflow READ of size 42, 0 bytes after 42-byte region.
PSIRT Ticket: PSIRTSUPT-19737


Note You need to log in before you can comment on or make changes to this bug.