Fedora Account System
Red Hat Associate
Red Hat Customer
A 4-byte heap-buffer-overflow (out-of-bounds read) was found in gst-plugins-good's Matroska demuxer, in the function gst_matroska_parse_flac_stream_headers() in gst/matroska/matroska-ids.c. When parsing FLAC codec private data embedded in a Matroska (MKV/WebM) container, the function iterates over FLAC metadata blocks. Each block has a 4-byte header (1 byte flags + 3 bytes length) followed by a body of 'len' bytes. The bounds check at line 309 validates 'off + len > codec_data_size' but the subsequent gst_buffer_new_memdup() at line 314 copies 'len + 4' bytes (body + header). When off + len == codec_data_size, the guard passes but the memdup reads 4 bytes past the end of the heap-allocated codec_data buffer. The correct check should be 'off + 4 + len > codec_data_size'. This function is called from matroska-demux.c line 7397 when processing A_FLAC audio tracks. Affected versions: <= 1.28.5 Fixed in version: 1.28.6 (upcoming) Fix MR: https://gitlab.freedesktop.org/gstreamer/gstreamer-security/-/merge_requests/111 (GST-SA-2026-0073) Reporter: Yazan Balawneh, CyStack Security Team ASan confirmation on GStreamer 1.28.4, Kali Linux x86_64: heap-buffer-overflow READ of size 42, 0 bytes after 42-byte region. PSIRT Ticket: PSIRTSUPT-19737