Junglewise Threat Intelligence

CVE-2026-3086: GStreamer H.266 Codec Parser out-of-bounds write in APS units

CVE-2026-3086 · Severity: high · CVSS 7.8 · Published 2026-03-16

Technologies: Gstreamer Gst-Plugins-Bad, Red Hat Enterprise Linux 6, Gstreamer, Red Hat Enterprise Linux 8. Vendors: Gstreamer, Red Hat.

Executive brief

GStreamer is a widely used multimedia framework for handling audio and video playback. A vulnerability in its H.266 video processing component could allow an attacker to execute malicious code if a user opens a specially crafted video file. This could lead to a full system compromise or unauthorized access to sensitive data on the affected machine.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists in the GStreamer H.266 video bitstream parser within the 'gst-plugins-bad' package. The flaw is located in the processing of Adaptation Parameter Set (APS) units, where a lack of proper validation of user-supplied data allows a write past the end of an allocated buffer. While categorized as local/user-interaction required, the vulnerability can be triggered by any application utilizing the GStreamer library to parse malicious H.266 video streams. Successful exploitation can lead to arbitrary code execution in the context of the current process. The issue is addressed in GStreamer version 1.28.1.

Affected products

  • GStreamer GStreamer gst-plugins-bad < 1.28.1
  • Red Hat Enterprise Linux 6 affected
  • Red Hat Enterprise Linux 8 affected

Timeline

  • 2026-02-11: disclosed: Vulnerability reported to vendor
  • 2026-02-25: patched: Fix committed to GStreamer repository
  • 2026-03-06: advisory: Coordinated public release of ZDI advisory
  • 2026-03-16: advisory: NVD publication date

References

Related threats