Executive brief
A security flaw exists in the GStreamer component responsible for decoding WavPack audio files. By tricking a user into opening a specially crafted audio file, an attacker can cause the application to crash or potentially execute unauthorized code. This could lead to a loss of service or a compromise of the user's system and data.
Technical details
An integer overflow vulnerability exists in the gst_wavpack_dec_handle_frame() function within GStreamer's gst-plugins-good. The flaw occurs during the buffer size calculation (4 * block_samples * channels), where 32-bit arithmetic is used before promotion to a larger allocation size type. This results in a small heap allocation followed by a large out-of-bounds write by the WavPack library. A remote attacker can exploit this by providing a crafted WavPack file, leading to heap memory corruption, application crashes, or arbitrary code execution. The issue is addressed in GStreamer version 1.28.4.
Affected products
- GStreamer gst-plugins-good versions prior to 1.28.4
Timeline
- 2026-06-10: other: Reported to Red Hat Bugzilla
- 2026-06-15: disclosed: Public disclosure of CVE-2026-53705