Executive brief
GStreamer is a multimedia framework used to build media players, video editors, and other applications. A stack-based buffer overflow in the Opus audio decoder can be triggered by processing specially crafted audio files with excessive channel counts, allowing attackers to crash applications or execute arbitrary code.
Technical details
A stack-based and heap-based buffer overflow exists in the Opus audio decoder within gst-plugins-base when processing Opus streams with more than 64 channels. The vulnerability stems from insufficient validation of the channel count field in the stream header; the decoder uses this untrusted value to determine the size of memory operations on fixed-size 64-element arrays, resulting in out-of-bounds writes. Exploitation requires user interaction (opening a malicious audio file or visiting a malicious page), but no authentication is needed. An attacker can trigger application crashes, denial of service, data corruption, or potentially achieve arbitrary code execution through stack manipulation or pointer corruption. The vulnerability was patched in GStreamer gst-plugins-base version 1.28.5 and later.
Affected products
- GStreamer gst-plugins-base < 1.28.5
Timeline
- 2026-05-21: disclosed: Vulnerability reported to vendor
- 2026-07-29: patched: GStreamer gst-plugins-base 1.28.5 released with fix
- 2026-07-29: advisory: ZDI and CVE advisory published