Junglewise Threat Intelligence

CVE-2026-53705: GStreamer gst-plugins-good heap overflow in WavPack decoder

CVE-2026-53705 · Severity: high · CVSS 7.6 · Published 2026-06-15

Vendors: Gstreamer.

Executive brief

A security flaw exists in the GStreamer component responsible for decoding WavPack audio files. By tricking a user into opening a specially crafted audio file, an attacker can cause the application to crash or potentially execute unauthorized code. This could lead to a loss of service or a compromise of the user's system and data.

Technical details

An integer overflow vulnerability exists in the gst_wavpack_dec_handle_frame() function within GStreamer's gst-plugins-good. The flaw occurs during the buffer size calculation (4 * block_samples * channels), where 32-bit arithmetic is used before promotion to a larger allocation size type. This results in a small heap allocation followed by a large out-of-bounds write by the WavPack library. A remote attacker can exploit this by providing a crafted WavPack file, leading to heap memory corruption, application crashes, or arbitrary code execution. The issue is addressed in GStreamer version 1.28.4.

Affected products

  • GStreamer gst-plugins-good versions prior to 1.28.4

Timeline

  • 2026-06-10: other: Reported to Red Hat Bugzilla
  • 2026-06-15: disclosed: Public disclosure of CVE-2026-53705

References