Junglewise Threat Intelligence

CVE-2026-2921: GStreamer RIFF palette integer overflow in AVI handling

CVE-2026-2921 · Severity: high · CVSS 7.8 · Published 2026-03-16

Technologies: Red Hat Enterprise Linux, Gstreamer. Vendors: Debian, Gstreamer, Red Hat.

Executive brief

GStreamer is a widely used multimedia framework that allows applications to process audio and video data. A vulnerability in how it handles AVI video files could allow an attacker to execute malicious code on a user's system if they are tricked into opening a specially crafted media file. This could lead to a full system compromise, unauthorized data access, or service disruptions depending on the application using the library.

Technical details

An integer overflow vulnerability exists in the GStreamer RIFF parser, specifically within the handling of palette data in AVI files. The flaw stems from insufficient validation of user-supplied palette data, which leads to an integer overflow before memory write operations. An attacker can exploit this by providing a malformed AVI file that, when processed by the library, triggers out-of-bounds reads and writes to heap memory. Successful exploitation allows for arbitrary code execution in the context of the process using the GStreamer library. The issue is addressed in GStreamer gst-plugins-base version 1.28.1.

Affected products

  • GStreamer gst-plugins-base < 1.28.1
  • Red Hat Enterprise Linux 8, 10, 10.2, 7 ELS
  • Debian gst-plugins-base1.0 1.18.4-2+deb11u5

Timeline

  • 2026-02-11: disclosed: Vulnerability reported to vendor
  • 2026-02-13: patched: Initial patch authored in GStreamer GitLab
  • 2026-02-25: advisory: GStreamer project advisory SA-2026-0004 released
  • 2026-03-06: advisory: Coordinated public release by ZDI
  • 2026-03-16: advisory: NVD publication date

References

Related threats