CVE Record
[ HIGH ] CVE-2026-19387
GStreamer ADPCM Decoder Heap Out-of-Bounds Write
Heap OOB write in GStreamer's ADPCM decoder lets crafted WAV files trigger memory corruption and potential code execution in gst-plugins-bad.
- Vendor
- GStreamer Project
- Product
- gst-plugins-bad
- CVSS
- 7.6
- EPSS (exploit probability)
- N/A
- Status
- patched
- Published
Insufficient validation of the per-block sample count in the IMA/DVI ADPCM decoder (adpcmdec element, gst-plugins-bad) allows a crafted multi-channel WAV file to write beyond the allocated output buffer. Outcome ranges from application crash to memory corruption; Red Hat lists arbitrary code execution as a potential worst case.
Patch: update gst-plugins-bad from your distribution’s package repository. Red Hat advisory: CVE-2026-19387.
