Junglewise Threat Intelligence

CVE-2026-2922: GStreamer RealMedia Demuxer out-of-bounds write

CVE-2026-2922 · Severity: high · CVSS 7.8 · Published 2026-03-16

Technologies: Red Hat Enterprise Linux AppStream, Gstreamer, Gstreamer Gst-Plugins-Ugly. Vendors: Red Hat, Gstreamer.

Executive brief

GStreamer is a widely used multimedia framework that allows applications to process audio and video. A vulnerability in its RealMedia file processing component could allow an attacker to execute malicious code on a user's system if they are tricked into opening a specially crafted video file. This could lead to a full system compromise, data theft, or unauthorized access to the user's environment.

Technical details

An out-of-bounds write vulnerability exists in the GStreamer RealMedia demuxer (part of gst-plugins-ugly) during the processing of video packets. The flaw is caused by a lack of proper validation of user-supplied data, leading to a write past the end of an allocated heap buffer. While categorized as a remote code execution risk, exploitation typically requires a user to open a malicious media file (Local attack vector with Required User Interaction). Successful exploitation allows an attacker to execute arbitrary code within the context of the process using the GStreamer library. The issue is addressed in GStreamer gst-plugins-ugly version 1.28.1.

Affected products

  • GStreamer GStreamer gst-plugins-ugly < 1.28.1
  • Red Hat Red Hat Enterprise Linux AppStream (v. 9)
  • Red Hat Red Hat Enterprise Linux AppStream (v. 10)

Timeline

  • 2026-02-11: disclosed: Vulnerability reported to vendor
  • 2026-02-25: patched: GStreamer project fix date
  • 2026-03-06: advisory: Coordinated public release by ZDI
  • 2026-03-16: advisory: NVD publication date

References

Related threats