Junglewise Threat Intelligence

CVE-2026-3085: GStreamer heap overflow in rtpqdm2depay element

CVE-2026-3085 · Severity: high · CVSS 8.8 · Published 2026-03-16

Technologies: Gstreamer, Red Hat Enterprise Linux. Vendors: Gstreamer, Red Hat.

Executive brief

GStreamer is a widely used framework for handling multimedia content like video and audio. A vulnerability in its RTP QDM2 component could allow a remote attacker to execute malicious code on a user's system if they are tricked into processing a specially crafted media stream. This could lead to a full system compromise, unauthorized data access, or service disruptions.

Technical details

A heap-based buffer overflow exists in the GStreamer 'rtpqdm2depay' element within the gst-plugins-good package. The flaw is located in the processing of X-QDM RTP payloads, where the application fails to properly validate the length of user-supplied data before copying it into a heap-resident buffer. A remote attacker can exploit this by providing a malicious RTP stream, requiring some level of user interaction (such as opening a stream or visiting a site that triggers the library). Successful exploitation allows for arbitrary code execution in the context of the process using the GStreamer library. The issue is addressed in GStreamer version 1.28.1 and various Red Hat security updates.

Affected products

  • GStreamer GStreamer gst-plugins-good 1.28 < 1.28.1, 1.x <= 1.28.10
  • Red Hat Enterprise Linux 8, 9, 10

Timeline

  • 2026-02-11: disclosed: Vulnerability reported to vendor
  • 2026-02-13: patched: Initial patch committed to GStreamer repository
  • 2026-02-25: advisory: GStreamer project advisory SA-2026-0008 released
  • 2026-03-06: advisory: ZDI public advisory released
  • 2026-03-16: advisory: NVD publication date
  • 2026-05-19: patched: Red Hat released security updates (RHSA-2026:19024, RHSA-2026:19180)

References

Related threats