Skip to content
Red HatCVE-2026-17072

Red Hat GStreamer: out-of-bounds read

Low3.3CVE-2026-17072 · Published Jul 28, 2026

A flaw was found in GStreamer's gst-plugins-good. A heap-based out-of-bounds read of 4 bytes can occur when parsing FLAC audio stream headers embedded in a Matroska or WebM container file. The vulnerability is triggered by a boundary check that does not account for the full size of the data being copied, allowing a small read past the end of the allocated buffer. An attacker could exploit this by crafting a malicious Matroska or WebM file and tricking a user into opening it, potentially leaking a small amount of adjacent heap memory.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat Enterprise Linux 10
Product
all versionsNo fix yet
Red Hat Enterprise Linux 6
Product
all versionsNo fix yet
Red Hat Enterprise Linux 7
Product
all versionsNo fix yet
all versionsNo fix yet
Red Hat Enterprise Linux 8
Product
all versionsNo fix yet
Red Hat Enterprise Linux 9
Product
all versionsNo fix yet
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat CRIU: code injection
High7.8Jul 28
Red Hat sg3_utils. The sg_inq command: code execution
High7.6Jul 28
A flaw was found in openshift/oauth-proxy
High8.5Jul 28
Red Hat Dogtag PKI: denial of service
Medium6.5Jul 28
Red Hat file-sgi plugin: integer overflow
Medium5.5Jul 27
Red Hat file-fits plugin: integer overflow
High7.8Jul 27

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.