Junglewise Threat Intelligence

CVE-2026-3084: GStreamer H.266 Codec Parser integer underflow in picture partitions

CVE-2026-3084 · Severity: high · CVSS 7.8 · Published 2026-03-16

Technologies: Gstreamer Gst-Plugins-Bad, Red Hat Enterprise Linux 6, Gstreamer, Red Hat Enterprise Linux 8. Vendors: Gstreamer, Red Hat.

Executive brief

GStreamer is a widely used multimedia framework for processing audio and video. A security flaw in its H.266 video codec parser could allow an attacker to execute malicious code on a user's system if they are tricked into opening a specially crafted video file. This could lead to a full system compromise, data theft, or unauthorized access to the user's environment.

Technical details

An integer underflow vulnerability exists in the GStreamer H.266 video bitstream parser within the 'gst-plugins-bad' package. The flaw is located in the parsing of picture partitions, where a lack of proper validation of user-supplied data leads to an underflow before a memory write operation. While categorized as local/user-interaction required, an attacker can exploit this by providing a malicious H.266 video file to an application using the GStreamer library. Successful exploitation can result in an out-of-bounds write, potentially leading to arbitrary code execution in the context of the process. The issue is addressed in GStreamer version 1.28.1.

Affected products

  • GStreamer GStreamer gst-plugins-bad < 1.28.1
  • Red Hat Enterprise Linux 6 affected
  • Red Hat Enterprise Linux 8 affected

Timeline

  • 2026-02-11: disclosed: Vulnerability reported to vendor
  • 2026-02-25: patched: Fix committed to GStreamer repository
  • 2026-03-06: advisory: Coordinated public release of ZDI advisory
  • 2026-03-16: advisory: NVD publication date

References

Related threats