Red HatCVE-2026-19387
Red Hat GStreamer gst-plugins-bad adpcmdec element: out-of-bounds write
High7.6CVE-2026-19387 · Published Aug 10, 2026 · updated Sep 18, 2026
A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio. Insufficient validation of the per-block sample count for multi-channel streams allows a crafted WAV file to cause writes beyond the allocated output buffer. This can lead to application crash, denial of service, memory corruption, or potentially arbitrary code execution when untrusted media is processed.
Affected versions
The source does not list versions here. See the source advisory for affected products and fixes.
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-787
- www.cve.org/CVERecord?id=CVE-2026-19387
- nvd.nist.gov/vuln/detail/CVE-2026-19387
- access.redhat.com/errata/RHSA-2026:55433
- access.redhat.com/errata/RHSA-2026:55865
- access.redhat.com/errata/RHSA-2026:56521
- access.redhat.com/errata/RHSA-2026:65122
- access.redhat.com/errata/RHSA-2026:65123
- access.redhat.com/errata/RHSA-2026:65124
- access.redhat.com/errata/RHSA-2026:66406
- access.redhat.com/errata/RHSA-2026:66407
- access.redhat.com/errata/RHSA-2026:67151
- access.redhat.com/errata/RHSA-2026:67844
- access.redhat.com/errata/RHSA-2026:67861
- access.redhat.com/security/cve/CVE-2026-19387
- bugzilla.redhat.com/show_bug.cgi?id=2513015
- gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12235
- gstreamer.freedesktop.org/releases/1.28/
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 10 | Red Hat QEMU: memory corruption | Medium4.4 | No fix yet |
| Aug 10 | Red Hat Enterprise Linux: denial of service | Low3.9 | No fix yet |
| Aug 10 | Red Hat Enterprise Linux 10: privilege escalation | High7.8 | No fix yet |
| Aug 10 | Red Hat OpenShift AI (RHOAI): denial of service | High8.5 | No fix yet |
| Aug 10 | Red Hat OpenShift AI (RHOAI): remote code execution | Critical9.9 | No fix yet |
| Aug 10 | Red Hat OpenShift AI (RHOAI): privilege escalation | High8.8 | No fix yet |