{"id":"CVE-2026-12891","title":"Gstreamer1-plugins-bad-free: gstreamer1-plugins-bad: global buffer overflow (oob read) in h.266/vvc vui parameter parser","summary":"A flaw was found in the GStreamer gst-plugins-bad package. When processing a malformed H.266/VVC video stream with a crafted aspect ratio indicator value, the H.266 parser performs an out-of-bounds read of up to 8 bytes from adjacent mem…","severity":"medium","cvss":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N","cvssSource":"cna","cwe":["CWE-125"],"vendor":"Red Hat","product":"gstreamer1-plugins-bad-free","affected":["gstreamer1-plugins-bad-free (all versions)","gstreamer1-plugins-bad-free (all versions)","gstreamer1-plugins-bad-free (all versions)"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-06-24T13:06:59.873615Z"},"published":"2026-06-23","updated":"2026-09-10","sourceUpdated":"2026-09-10T17:23:04.482Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2026-12891","references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-12891"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2491318","label":"RHBZ#2491318"},{"url":"https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5109"}],"tags":["cve.org"],"epss":0.00272,"epssPercentile":0.1981,"ingestedAt":"2026-09-11T11:32:42.886Z","slug":"CVE-2026-12891","body":"## Overview\n\nA flaw was found in the GStreamer gst-plugins-bad package. When processing a malformed H.266/VVC video stream with a crafted aspect ratio indicator value, the H.266 parser performs an out-of-bounds read of up to 8 bytes from adjacent memory. This flaw allows an attacker to craft a malicious H.266 video file or stream that, when processed by a GStreamer-based application, could leak limited memory contents through video metadata, potentially exposing sensitive information from the application's address space.\n\n## Affected\n\n- `gstreamer1-plugins-bad-free (all versions)`\n- `gstreamer1-plugins-bad-free (all versions)`\n- `gstreamer1-plugins-bad-free (all versions)`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n### Workarounds\n\nNo mitigation is currently available that meets Red Hat Product Security's standards for usability, deployment, applicability, or stability.","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":23.7,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}