Fedora Account System
Red Hat Associate
Red Hat Customer
A flaw was found in GStreamer gst-plugins-ugly (asfdemux). The ASF demuxer performed arithmetic on attacker-controlled length and size fields from ASF/WMV/WMA headers using 32-bit unsigned operations without adequate overflow and underflow checks. In gst_asf_demux_process_metadata(), summing name_len and data_len could wrap, bypassing the available-data check and causing g_convert() to read beyond the heap buffer during UTF-16LE to UTF-8 conversion. Related underflow issues in other header parsers similarly produced oversized lengths and out-of-bounds reads. Because asfdemux is auto-plugged by playbin and decodebin, processing a crafted file can crash the application (denial of service) and may enable limited heap information disclosure via metadata handling. Fixed upstream in gst-plugins-ugly 1.28.6 (GStreamer-SA-2026-0075).
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:55435 https://access.redhat.com/errata/RHSA-2026:55435