Junglewise Threat Intelligence

CVE-2025-47219: GStreamer isomp4 plugin out-of-bounds read in qtdemux_parse_trak

CVE-2025-47219 · Severity: high · CVSS 8.1 · Published 2025-08-07

Technologies: Gstreamer, Siemens SIMATIC CN 4100. Vendors: Gstreamer, Siemens.

Executive brief

GStreamer is a widely used multimedia framework for processing audio and video. A vulnerability in its MP4 file processing component could allow an attacker to trigger a system crash or potentially access sensitive information from the computer's memory by providing a specially crafted video file. This affects various applications and industrial hardware, such as Siemens SIMATIC CN 4100, that rely on GStreamer for media handling.

Technical details

A heap-based out-of-bounds read vulnerability exists in GStreamer's 'isomp4' plugin, specifically within the 'qtdemux_parse_trak' function. The flaw is triggered during the parsing of malformed MP4 (QuickTime) files. An attacker can exploit this by providing a crafted media file that causes the parser to read beyond the allocated buffer boundaries. This can result in the disclosure of sensitive memory contents or a denial-of-service (DoS) condition via an application crash. The vulnerability is present in GStreamer versions through 1.26.1 and has been addressed in version 1.26.2. Siemens has also identified this vulnerability as affecting SIMATIC CN 4100 devices prior to version V5.0.

Affected products

  • GStreamer project GStreamer gst-plugins-good < 1.26.2
  • GStreamer project GStreamer gst-plugins-base < 1.26.2
  • Siemens SIMATIC CN 4100 < V5.0

Timeline

  • 2025-05-29: advisory: GStreamer project internal advisory date
  • 2025-08-07: disclosed: Initial CVE publication
  • 2026-05-12: advisory: Siemens published advisory SSA-032379 covering this CVE in SIMATIC CN 4100

References

Related threats