Junglewise Threat Intelligence

CVE-2026-88914: GStreamer gst-plugins-good integer overflow in CEA-608 caption parser

CVE-2026-88914 · Severity: medium · CVSS 4.4 · Published 2026-09-11

Vendors: Gstreamer.

Executive brief

GStreamer is a multimedia framework used to play and process audio and video files. The isomp4 plugin, which handles MP4 and MOV video files, contains a flaw in its closed-caption parser that can be exploited when a user opens a specially crafted media file. An attacker could trick users into playing a malicious file to leak small amounts of memory from the application or cause it to crash.

Technical details

An integer overflow vulnerability exists in the CEA-608 closed-caption parser within GStreamer's qtdemux component (part of gst-plugins-good). The flaw occurs in 32-bit unsigned arithmetic used in a bounds check; when processing a malicious MP4 or MOV file with crafted caption data, the overflow can bypass the bounds check, leading to an out-of-bounds heap read of up to 244 bytes. The vulnerability requires user interaction (opening a malicious media file) and is local to the affected system. The read-only nature of this flaw prevents code execution but allows heap memory disclosure and potential application crash. A patch is available upstream in the GStreamer merge request.

Affected products

  • GStreamer gst-plugins-good <UNKNOWN>

Timeline

  • 2026-09-11: disclosed

References