Executive brief
GStreamer's image decoding component (gst-plugins-good) fails to properly resize output buffers when processing image sequences with varying frame dimensions. An attacker can craft a malicious image sequence that triggers a heap buffer overflow when decoded, potentially allowing arbitrary code execution on systems that process untrusted images or video files.
Technical details
A heap buffer overflow exists in the gdkpixbufdec element of gst-plugins-good, which decodes images using the GdkPixbuf library. The vulnerability occurs because the decoder initializes its output buffer pool based on the dimensions of the first decoded frame and never re-evaluates or reconfigures it when subsequent frames have different dimensions or pixel formats. When processing image sequences where later frames are larger than the first frame, the decoder acquires undersized buffers from the stale pool and writes decoded pixel data beyond the buffer boundary. An attacker can trigger this overflow by providing a crafted image sequence with frames of increasing dimensions through network streams, container files, or local files; user interaction is required to trigger the vulnerability (visiting a malicious page or opening a malicious file). The overflow can result in a crash, denial of service, data corruption, or arbitrary code execution in the context of the application. The issue is fixed in gst-plugins-good 1.28.5, which re-evaluates the output buffer pool whenever frame dimensions or pixel formats change, and lowered the element's rank to prevent auto-selection for decoding untrusted images.
Affected products
- GStreamer gst-plugins-good < 1.28.5
Timeline
- 2026-05-21: disclosed: Vulnerability reported to vendor
- 2026-07-29: advisory: ZDI-26-466 advisory published; coordinated public release
- 2026-07-08: advisory: GStreamer Security Advisory 2026-0052 (CVE-2026-18298)
- 2026-08-20: patched: gst-plugins-good 1.28.5 released with fix