CVE Record
[ HIGH ] CVE-2026-19389
GStreamer ASF Demuxer Integer Overflow/Underflow
Integer overflow and underflow in GStreamer's ASF demuxer let crafted ASF, WMV, or WMA headers bypass bounds checks, triggering out-of-bounds heap reads in gst-plugins-ugly.
- Vendor
- GStreamer Project
- Product
- gst-plugins-ugly
- CVSS
- 7.1
- EPSS (exploit probability)
- N/A
- Status
- patched
- Published
Multiple integer overflow and underflow flaws in the ASF demuxer component of gst-plugins-ugly allow attacker-controlled length and size values parsed from .asf, .wmv, or .wma file headers to bypass bounds checks. The result is out-of-bounds heap reads that can lead to crash, denial of service, or limited information disclosure.
Patch: update gst-plugins-ugly from your distribution. Red Hat advisory: CVE-2026-19389.
