{"id":"CVE-2026-85150","title":"A NULL pointer dereference flaw was found in GStreamer's RTSP support library","summary":"A NULL pointer dereference flaw was found in GStreamer's RTSP support library. The vulnerability occurs while parsing an Authorization or WWW-Authenticate header that uses Digest authentication. Specially crafted whitespace placement aro…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-476"],"vendor":"Red Hat","product":"gstreamer1-plugins-base","affected":["gstreamer1-plugins-base (all versions)","gstreamer1-plugins-base (all versions)","gstreamer1-plugins-base (all versions)","gstreamer1-plugins-base (all versions)"],"published":"2026-09-03","updated":"2026-09-21","sourceUpdated":"2026-09-21T18:17:11.550","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-85150","references":[{"url":"https://access.redhat.com/errata/RHSA-2026:66460","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:67145","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:69100","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2026-85150","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2527936","label":"secalert@redhat.com"},{"url":"https://gitlab.freedesktop.org/gstreamer/gstreamer-security/-/merge_requests/120","label":"secalert@redhat.com"},{"url":"https://gitlab.freedesktop.org/gstreamer/gstreamer/-/blob/main/subprojects/gst-plugins-base/gst-libs/gst/rtsp/gstrtspmessage.c#L1408","label":"secalert@redhat.com"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-85150.json"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-85150"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-85150"}],"tags":["nvd","cve.org","csaf","vex","red-hat"],"epss":0.0053,"epssPercentile":0.42437,"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"partial","timestamp":"2026-09-03T12:33:40.281754Z"},"ingestedAt":"2026-09-14T15:23:07.465Z","patched":["enterprise_linux_appstream_v_10","enterprise_linux_appstream_v_8","enterprise_linux_appstream_v_9"],"slug":"CVE-2026-85150","body":"## Overview\n\nA NULL pointer dereference flaw was found in GStreamer's RTSP support library. The vulnerability occurs while parsing an Authorization or WWW-Authenticate header that uses Digest authentication. Specially crafted whitespace placement around a parameter's terminator can cause an internal length calculation to underflow, leading to a crash of the process parsing the header. On an RTSP server this can be triggered by a remote, unauthenticated attacker sending a single malformed request when the server has authentication enabled; the same flaw can also be triggered against an RTSP client by a malicious or compromised RTSP server. Successful exploitation results in a denial of service (application crash) and has no confirmed impact on confidentiality or integrity.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **RHSA-2026:66460** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2026-09-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:66460)\n- **RHSA-2026:67145** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8) · released 2026-09-14 · [advisory](https://access.redhat.com/errata/RHSA-2026:67145)\n- **RHSA-2026:69100** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9) · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69100)\n- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 7 · no fix planned: Red Hat Enterprise Linux 7 · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-85150.json)","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}