Executive brief
GStreamer, a widely used multimedia framework for handling audio and video, contains a vulnerability in its H.266 video processing component. An attacker could exploit this by tricking a user into opening a specially crafted video file, potentially leading to a complete system compromise or application crash. This could allow unauthorized access to sensitive data or disrupt business operations that rely on media processing.
Technical details
A stack-based buffer overflow exists in the GStreamer H.266 video bitstream parser, specifically within the gst-plugins-bad package. The flaw occurs during the parsing of 'pic_timing' Supplemental Enhancement Information (SEI) messages due to insufficient validation of user-supplied data lengths before copying to a fixed-length stack buffer. An attacker can exploit this by providing a malicious H.266 video stream, requiring user interaction (e.g., opening a file). Successful exploitation can lead to arbitrary code execution in the context of the process using the library. The issue is addressed in GStreamer version 1.28.1.
Affected products
- GStreamer gst-plugins-bad < 1.28.1
- GStreamer GStreamer < 1.28.1
Timeline
- 2026-02-11: disclosed: Vulnerability reported to vendor
- 2026-02-25: patched: Fix committed to GStreamer repository
- 2026-03-06: advisory: Coordinated public release of ZDI advisory
- 2026-03-16: advisory: NVD publication date
References
- https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/2ffdfca2df95a7f605c922d3111e5d5be5314dca
- https://www.zerodayinitiative.com/advisories/ZDI-26-162/
- https://access.redhat.com/security/cve/CVE-2026-3081
- https://bugzilla.redhat.com/show_bug.cgi?id=2447494
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-3081.json