{"id":"CVE-2026-52722","title":"A signed integer overflow vulnerability was found in GStreamer's VMnc decoder","summary":"A signed integer overflow vulnerability was found in GStreamer's VMnc decoder. A crafted VMnc stream with large cursor dimensions can overflow signed integer payload-size arithmetic, bypassing a length check and leading to out-of-bounds …","severity":"high","cvss":7.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","cwe":["CWE-190","CWE-190"],"published":"2026-06-15","updated":"2026-07-28","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-52722","references":[{"url":"https://access.redhat.com/errata/RHSA-2026:36749","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:36834","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:37130","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:47069","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:47070","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:47071","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:47075","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:47076","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:47176","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2026-52722","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2486733","label":"secalert@redhat.com"},{"url":"https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5107","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:36749","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:36834","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:37130","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/security/cve/CVE-2026-52722","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2486733","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-52722.json","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"tags":["nvd"],"epss":0.00392,"epssPercentile":0.3315,"ingestedAt":"2026-07-28T21:39:18.114Z","slug":"CVE-2026-52722","body":"## Overview\n\nA signed integer overflow vulnerability was found in GStreamer's VMnc decoder. A crafted VMnc stream with large cursor dimensions can overflow signed integer payload-size arithmetic, bypassing a length check and leading to out-of-bounds reads. A remote attacker could trick a user into opening a specially crafted VMnc file, potentially causing a crash or information disclosure.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":39.1,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}