CVE-2026-19389

7.1

Red Hat · Red Hat Enterprise Linux

Multiple integer overflow and underflow vulnerabilities in the GStreamer gst-plugins-ugly ASF demuxer allow for potential denial of service via specially crafted media files.

Executive summary

A critical vulnerability in the GStreamer ASF demuxer affects multiple versions of Red Hat Enterprise Linux and may lead to application crashes or denial of service.

Vulnerability

This vulnerability involves integer overflow and underflow flaws within the ASF demuxer component of GStreamer. An unauthenticated, remote attacker can trigger these conditions by providing a malformed ASF, WMV, or WMA file, requiring user interaction to process the malicious media.

Business impact

The exploitation of this flaw can result in significant service instability or complete application failure, categorized as a high severity risk with a CVSS score of 7.1. While information disclosure is limited, the impact on availability poses a direct threat to business continuity for systems that rely on media processing pipelines.

Remediation

Immediate Action: Update the GStreamer packages to the versions specified in the official Red Hat security advisory to address the demuxer flaws.

Proactive Monitoring: Monitor system logs for unexpected crashes or error messages associated with the GStreamer media framework.

Compensating Controls: Restrict the processing of untrusted media files from external sources until patches are successfully deployed across the environment.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the prevalence of media processing within enterprise environments, administrators should prioritize the deployment of the vendor-supplied patches. Failure to remediate could leave systems vulnerable to targeted crashes if users are induced to open malicious media files.

More Red Hat CVEs