Skip to content
feed: live
>_ 0dayNews
CVE Record
[ HIGH ] CVE-2026-19387

GStreamer ADPCM Decoder Heap Out-of-Bounds Write

Heap OOB write in GStreamer's ADPCM decoder lets crafted WAV files trigger memory corruption and potential code execution in gst-plugins-bad.

cat cve-2026-19387.json
Vendor
GStreamer Project
Product
gst-plugins-bad
CVSS
7.6
EPSS (exploit probability)
N/A
Status
patched
Published

Insufficient validation of the per-block sample count in the IMA/DVI ADPCM decoder (adpcmdec element, gst-plugins-bad) allows a crafted multi-channel WAV file to write beyond the allocated output buffer. Outcome ranges from application crash to memory corruption; Red Hat lists arbitrary code execution as a potential worst case.

Patch: update gst-plugins-bad from your distribution’s package repository. Red Hat advisory: CVE-2026-19387.