Executive brief
GStreamer is a multimedia framework used to play and process audio and video files. The isomp4 plugin, which handles MP4 and MOV video files, contains a flaw in its closed-caption parser that can be exploited when a user opens a specially crafted media file. An attacker could trick users into playing a malicious file to leak small amounts of memory from the application or cause it to crash.
Technical details
An integer overflow vulnerability exists in the CEA-608 closed-caption parser within GStreamer's qtdemux component (part of gst-plugins-good). The flaw occurs in 32-bit unsigned arithmetic used in a bounds check; when processing a malicious MP4 or MOV file with crafted caption data, the overflow can bypass the bounds check, leading to an out-of-bounds heap read of up to 244 bytes. The vulnerability requires user interaction (opening a malicious media file) and is local to the affected system. The read-only nature of this flaw prevents code execution but allows heap memory disclosure and potential application crash. A patch is available upstream in the GStreamer merge request.
Affected products
- GStreamer gst-plugins-good <UNKNOWN>
Timeline
- 2026-09-11: disclosed