Executive brief
GStreamer is a widely used multimedia framework that allows applications to play and process video and audio files. A security flaw has been identified in how it handles certain video file formats, which could allow an attacker to execute malicious code on a user's system. This typically occurs if a user is tricked into opening a specially crafted video file or if an automated system, such as a file indexer, processes the malicious file in the background. Exploitation could lead to a full system compromise or unauthorized access to the user's data.
Technical details
A stack-based buffer overflow exists in the GStreamer 'qtdemux' element (part of gst-plugins-good) due to improper validation of user-supplied data lengths within the UncompressedFrameConfigBox (uncC atom) structure. When parsing malformed MOV/MP4 files containing uncompressed video, the library fails to verify the length of data before copying it into a fixed-length stack buffer. An attacker can exploit this by providing a crafted media file that, when processed by an application using GStreamer (such as GNOME Videos or automated metadata indexers like tracker-miners), triggers the overflow to execute arbitrary code in the context of the current process. The vulnerability is addressed in GStreamer version 1.28.2.
Affected products
- GStreamer gst-plugins-good < 1.28.2
Timeline
- 2026-03-12: disclosed: Vulnerability reported to vendor
- 2026-04-07: patched: Fixed in gst-plugins-good 1.28.2 release
- 2026-04-15: advisory: ZDI advisory published
- 2026-07-29: advisory: NVD record published