Red HatCVE-2026-19389
Red Hat Enterprise Linux: integer overflow
High7.1CVE-2026-19389 · Published Aug 10, 2026 · updated Sep 16, 2026
Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdemux) when parsing header objects from crafted ASF, WMV, or WMA files. Insufficient validation of attacker-controlled length and size values can bypass bounds checks and cause out-of-bounds heap reads. This can result in application crash, denial of service, or limited information disclosure when untrusted media is processed.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Red Hat Enterprise Linux 7 Product | all versions | No fix yet |
| Red Hat Enterprise Linux 8 Product | all versions | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-190
- www.cve.org/CVERecord?id=CVE-2026-19389
- nvd.nist.gov/vuln/detail/CVE-2026-19389
- access.redhat.com/errata/RHSA-2026:55435
- access.redhat.com/errata/RHSA-2026:55865
- access.redhat.com/errata/RHSA-2026:67882
- access.redhat.com/errata/RHSA-2026:67883
- access.redhat.com/errata/RHSA-2026:67930
- access.redhat.com/errata/RHSA-2026:67931
- access.redhat.com/security/cve/CVE-2026-19389
- bugzilla.redhat.com/show_bug.cgi?id=2513016
- gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12233
- gstreamer.freedesktop.org/releases/1.28/
- gstreamer.freedesktop.org/security/sa-2026-0075.html
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 10 | Red Hat QEMU: memory corruption | Medium4.4 | No fix yet |
| Aug 10 | Red Hat Enterprise Linux: denial of service | Low3.9 | No fix yet |
| Aug 10 | Red Hat Enterprise Linux 10: privilege escalation | High7.8 | No fix yet |
| Aug 10 | Red Hat OpenShift AI (RHOAI): denial of service | High8.5 | No fix yet |
| Aug 10 | Red Hat OpenShift AI (RHOAI): remote code execution | Critical9.9 | No fix yet |
| Aug 10 | Red Hat OpenShift AI (RHOAI): privilege escalation | High8.8 | No fix yet |