CVE-2026-19387
7.6Red Hat · Red Hat Enterprise Linux
A heap out-of-bounds write vulnerability in the GStreamer gst-plugins-bad adpcmdec element allows attackers to trigger crashes or potentially execute code via maliciously crafted audio files.
Executive summary
A heap out-of-bounds write vulnerability in GStreamer, affecting multiple versions of Red Hat Enterprise Linux, poses a risk of application crashes or arbitrary code execution.
Vulnerability
The flaw exists in the adpcmdec element of gst-plugins-bad, which fails to properly validate input during the decoding of IMA/DVI ADPCM audio data (CWE-787). This is an unauthenticated, remotely exploitable vulnerability that requires user interaction to process the malicious media file.
Business impact
The vulnerability carries a CVSS score of 7.6, reflecting the potential for remote code execution or denial of service through application crashes. This poses a significant threat to any system that processes external media, potentially leading to unauthorized access or widespread system instability.
Remediation
Immediate Action: Update the GStreamer packages to the latest version provided by Red Hat as soon as security advisories are published. Refer to the Red Hat Bugzilla entry 2513015 for specific package versioning.
Proactive Monitoring: Monitor systems for unusual crashes in media-processing applications or services that utilize GStreamer libraries.
Compensating Controls: Use endpoint protection software to scan incoming media files and restrict the execution of untrusted media applications.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Organizations should prioritize patching their RHEL environments. Until updates are applied, advise users to exercise extreme caution when opening unknown audio or video files from untrusted sources.