Fedora Account System
Red Hat Associate
Red Hat Customer
GStreamer RealMedia demuxer audio stream header OOB read. In gst_rmdemux_parse_mdpr(), audio header versions 4 and 5 read codec parameters at fixed byte offsets (22-69 for v4, 22-74 for v5) without bounds checking against the MDPR chunk length. OOB-read values control downstream buffer allocation, codec selection, and caps negotiation. No fix available; upstream recommends rmdemux rewrite. Reported via PSIRTSUPT-7239 by Tianshuo Han.