CVE-2026-1940
published 2026-03-23CVE-2026-1940: An incomplete fix for CVE-2024-47778 allows an out-of-bounds read in gst_wavparse_adtl_chunk() function. The patch added a size validation check lsize + 8 >…
PriorityP338high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.22%
13.1th percentile
An incomplete fix for CVE-2024-47778 allows an out-of-bounds read in gst_wavparse_adtl_chunk() function. The patch added a size validation check lsize + 8 > size, but it does not account for the GST_ROUND_UP_2(lsize) used in the actual offset calculation. When lsize is an odd number, the parser advances more bytes than validated, causing OOB read.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | gst-plugins-good1.0 | < gst-plugins-good1.0 1.28.1-1 (forky) | gst-plugins-good1.0 1.28.1-1 (forky) |
| freedesktop | gst-plugins-good | — | — |
| gstreamer | gstreamer | < 1.28.1 | 1.28.1 |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv5.1MEDIUM
vendor_debian5.1MEDIUM
vendor_redhat5.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
GStreamer Incomplete Fix CVE-2024-47778 gst_wavparse_adtl_chunk out-of-bounds (ID 4854 / WID-SEC-2026-0525)
vuldb·2026-04-13·CVSS 5.1
CVE-2026-1940 [MEDIUM] GStreamer Incomplete Fix CVE-2024-47778 gst_wavparse_adtl_chunk out-of-bounds (ID 4854 / WID-SEC-2026-0525)
A vulnerability has been found in GStreamer and classified as problematic. This affects the function gst_wavparse_adtl_chunk of the component Incomplete Fix CVE-2024-47778. The manipulation leads to out-of-bounds read.
This vulnerability is uniquely identified as CVE-2026-1940. Local access is required to approach this attack. No exploit exists.
It is recommended to apply a patch to fix this issue.
GHSA
GHSA-9wvw-r6fm-6wwv: An incomplete fix for CVE-2024-47778 allows an out-of-bounds read in gst_wavparse_adtl_chunk() function
ghsa_unreviewed·2026-03-24·CVSS 5.1
CVE-2026-1940 [MEDIUM] CWE-125 GHSA-9wvw-r6fm-6wwv: An incomplete fix for CVE-2024-47778 allows an out-of-bounds read in gst_wavparse_adtl_chunk() function
An incomplete fix for CVE-2024-47778 allows an out-of-bounds read in gst_wavparse_adtl_chunk() function. The patch added a size validation check lsize + 8 > size, but it does not account for the GST_ROUND_UP_2(lsize) used in the actual offset calculation. When lsize is an odd number, the parser advances more bytes than validated, causing OOB read.
OSV
CVE-2026-1940: An incomplete fix for CVE-2024-47778 allows an out-of-bounds read in gst_wavparse_adtl_chunk() function
osv·2026-03-23·CVSS 5.1
CVE-2026-1940 [MEDIUM] CVE-2026-1940: An incomplete fix for CVE-2024-47778 allows an out-of-bounds read in gst_wavparse_adtl_chunk() function
An incomplete fix for CVE-2024-47778 allows an out-of-bounds read in gst_wavparse_adtl_chunk() function. The patch added a size validation check lsize + 8 > size, but it does not account for the GST_ROUND_UP_2(lsize) used in the actual offset calculation. When lsize is an odd number, the parser advances more bytes than validated, causing OOB read.
Red Hat
gstreamer: incomplete fix of CVE-2026-1940
vendor_redhat·2026-02-25·CVSS 5.1
CVE-2026-1940 [MEDIUM] gstreamer: incomplete fix of CVE-2026-1940
gstreamer: incomplete fix of CVE-2026-1940
An incomplete fix for CVE-2024-47778 allows an out-of-bounds read in gst_wavparse_adtl_chunk() function. The patch added a size validation check lsize + 8 > size, but it does not account for the GST_ROUND_UP_2(lsize) used in the actual offset calculation. When lsize is an odd number, the parser advances more bytes than validated, causing OOB read.
An incomplete fix for CVE-2024-47778 allows an out-of-bounds read in gst_wavparse_adtl_chunk() function. The patch added a size validation check lsize + 8 > size, but it does not account for the GST_ROUND_UP_2(lsize) used in the actual offset calculation. When lsize is an odd number, the parser advances more bytes than validated, causing OOB read.
Package: gstreamer1 (Red Hat Enterprise Linux 10) - Fi
Debian
CVE-2026-1940: gst-plugins-good1.0 - An incomplete fix for CVE-2024-47778 allows an out-of-bounds read in gst_wavpars...
vendor_debian·2026·CVSS 5.1
CVE-2026-1940 [MEDIUM] CVE-2026-1940: gst-plugins-good1.0 - An incomplete fix for CVE-2024-47778 allows an out-of-bounds read in gst_wavpars...
An incomplete fix for CVE-2024-47778 allows an out-of-bounds read in gst_wavparse_adtl_chunk() function. The patch added a size validation check lsize + 8 > size, but it does not account for the GST_ROUND_UP_2(lsize) used in the actual offset calculation. When lsize is an odd number, the parser advances more bytes than validated, causing OOB read.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1.28.1-1)
sid: resolved (fixed in 1.28.1-1)
trixie: open
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-1940 cosmic-player: incomplete fix of CVE-2026-1940 [fedora-42]
bugzilla·2026-03-23·CVSS 7.5
CVE-2026-1940 [HIGH] CVE-2026-1940 cosmic-player: incomplete fix of CVE-2026-1940 [fedora-42]
CVE-2026-1940 cosmic-player: incomplete fix of CVE-2026-1940 [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be closed as EOL if it remains open with a
'version' of '42'.
Package Maintainer: If you wish for this bug to remain open because you
plan to fix it in a currently maintained version, change the 'version'
to
Bugzilla
CVE-2026-1940 gstreamer: incomplete fix of CVE-2026-1940
bugzilla·2026-02-04·CVSS 7.5
CVE-2026-1940 [HIGH] CVE-2026-1940 gstreamer: incomplete fix of CVE-2026-1940
CVE-2026-1940 gstreamer: incomplete fix of CVE-2026-1940
An incomplete fix for CVE-2024-47778 allows an out-of-bounds read in gst_wavparse_adtl_chunk() function. The patch added a size validation check lsize + 8 > size, but it does not account for the GST_ROUND_UP_2(lsize) used in the actual offset calculation. When lsize is an odd number, the parser advances more bytes than validated, causing OOB read.
Wiz
CVE-2026-1940 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.1
CVE-2026-1940 [MEDIUM] CVE-2026-1940 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-1940 :
Linux Debian vulnerability analysis and mitigation
An incomplete fix for CVE-2024-47778 allows an out-of-bounds read in gst_wavparse_adtl_chunk() function. The patch added a size validation check lsize + 8 > size, but it does not account for the GST_ROUND_UP_2(lsize) used in the actual offset calculation. When lsize is an odd number, the parser advances more bytes than validated, causing OOB read.
Source : NVD
## 5.1
Score
Published March 23, 2026
Severity MEDIUM
CNA Score 5.1
Affected Technologies
Linux Debian
Linux Red Hat
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 4.1
Exploitation Probability (EPSS) N/A
Affected packages and libraries
gstreamer
gstreamer
2026-03-23
Published