CVE-2026-12892
published 2026-06-23CVE-2026-12892: A flaw was found in GStreamer's gst-plugins-bad package. When processing a specially crafted H.264 video file containing malformed MVC or SVC extension slice…
PriorityP417medium4.4CVSS 3.1
AVLACLPRNUIRSUCLINAL
EPSS
0.12%
2.1th percentile
A flaw was found in GStreamer's gst-plugins-bad package. When processing a specially crafted H.264 video file containing malformed MVC or SVC extension slice NAL units, a 1-byte heap out-of-bounds read can occur during parsing. This happens when the parser attempts to check slice boundary information without first verifying that the NAL unit contains enough data beyond the extension header. An attacker could exploit this by tricking a user into opening a malicious H.264 video file, potentially causing the application to crash or leak a single byte of heap memory.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.14.4MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
vendor_redhat4.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
GStreamer out-of-bounds
vuldb·2026-06-23·CVSS 4.4
CVE-2026-12892 [MEDIUM] GStreamer out-of-bounds
A vulnerability was found in GStreamer. It has been classified as critical. Affected by this vulnerability is an unknown functionality. This manipulation causes out-of-bounds read.
This vulnerability is handled as CVE-2026-12892. The attack can be initiated remotely. There is not any exploit available.
GHSA
A flaw was found in GStreamer's gst-plugins-bad package.
ghsa_unreviewed·2026-06-23
CVE-2026-12892 [MEDIUM] CWE-125 A flaw was found in GStreamer's gst-plugins-bad package.
A flaw was found in GStreamer's gst-plugins-bad package. When processing a specially crafted H.264 video file containing malformed MVC or SVC extension slice NAL units, a 1-byte heap out-of-bounds read can occur during parsing. This happens when the parser attempts to check slice boundary information without first verifying that the NAL unit contains enough data beyond the extension header. An attacker could exploit this by tricking a user into opening a malicious H.264 video file, potentially causing the application to crash or leak a single byte of heap memory.
Red Hat
gstreamer1-plugins-bad: gstreamer1-plugins-bad: 1-byte heap out-of-bounds read in H.264 NAL extension slice parser
vendor_redhat·2026-06-22·CVSS 4.4
CVE-2026-12892 [MEDIUM] CWE-125 gstreamer1-plugins-bad: gstreamer1-plugins-bad: 1-byte heap out-of-bounds read in H.264 NAL extension slice parser
gstreamer1-plugins-bad: gstreamer1-plugins-bad: 1-byte heap out-of-bounds read in H.264 NAL extension slice parser
A flaw was found in GStreamer's gst-plugins-bad package. When processing a specially crafted H.264 video file containing malformed MVC or SVC extension slice NAL units, a 1-byte heap out-of-bounds read can occur during parsing. This happens when the parser attempts to check slice boundary information without first verifying that the NAL unit contains enough data beyond the extension header. An attacker could exploit this by tricking a user into opening a malicious H.264 video file, potentially causing the application to crash or leak a single byte of heap memory.
Statement: Red Hat product impact analysis pending. Component mapping required to determine which products ship t
No detection rules found.
No public exploits indexed.
2026-06-23
Published