Bug 2513016 (CVE-2026-19389) - CVE-2026-19389 gstreamer: gstreamer1-plugins-ugly-free: gstreamer: integer overflow/underflow in asfdemux bounds checks leading to out-of-bounds read
Summary: CVE-2026-19389 gstreamer: gstreamer1-plugins-ugly-free: gstreamer: integer ov...
Keywords:
Status: NEW
Alias: CVE-2026-19389
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2513019
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-10 02:50 UTC by OSIDB Bzimport
Modified: 2026-08-17 03:38 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:55435 0 None None None 2026-08-17 03:38:52 UTC

Description OSIDB Bzimport 2026-08-10 02:50:46 UTC
A flaw was found in GStreamer gst-plugins-ugly (asfdemux). The ASF demuxer performed arithmetic on attacker-controlled length and size fields from ASF/WMV/WMA headers using 32-bit unsigned operations without adequate overflow and underflow checks. In gst_asf_demux_process_metadata(), summing name_len and data_len could wrap, bypassing the available-data check and causing g_convert() to read beyond the heap buffer during UTF-16LE to UTF-8 conversion. Related underflow issues in other header parsers similarly produced oversized lengths and out-of-bounds reads. Because asfdemux is auto-plugged by playbin and decodebin, processing a crafted file can crash the application (denial of service) and may enable limited heap information disclosure via metadata handling. Fixed upstream in gst-plugins-ugly 1.28.6 (GStreamer-SA-2026-0075).

Comment 1 errata-xmlrpc 2026-08-17 03:38:52 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:55435 https://access.redhat.com/errata/RHSA-2026:55435


Note You need to log in before you can comment on or make changes to this bug.