Red HatCVE-2026-59692
Red Hat GStreamer: buffer overflow
High7.5CVE-2026-59692 · Published Jul 9, 2026 · updated Aug 19, 2026
A stack buffer overflow vulnerability was found in GStreamer's DTLS plugin. During a DTLS handshake, the peer certificate Subject Distinguished Name is printed into a fixed-size 2048-byte stack buffer without bounds checking. A remote unauthenticated attacker can send a certificate with an oversized Subject DN that exceeds the buffer, causing a stack buffer overflow and process crash, resulting in denial of service.
Affected versions
The source does not list versions here. See the source advisory for affected products and fixes.
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-121
- www.cve.org/CVERecord?id=CVE-2026-59692
- nvd.nist.gov/vuln/detail/CVE-2026-59692
- access.redhat.com/errata/RHSA-2026:47179
- access.redhat.com/errata/RHSA-2026:47180
- access.redhat.com/errata/RHSA-2026:47731
- access.redhat.com/errata/RHSA-2026:54658
- access.redhat.com/errata/RHSA-2026:54659
- access.redhat.com/errata/RHSA-2026:54660
- access.redhat.com/errata/RHSA-2026:54664
- access.redhat.com/errata/RHSA-2026:54665
- access.redhat.com/errata/RHSA-2026:54752
- access.redhat.com/errata/RHSA-2026:56658
- access.redhat.com/errata/RHSA-2026:56772
- access.redhat.com/security/cve/CVE-2026-59692
- bugzilla.redhat.com/show_bug.cgi?id=2497344
- gitlab.freedesktop.org/gstreamer/gstreamer-security/-/merge_requests/99
- gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5172
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 10 | Red Hat: server-side request forgery | Critical9.3 | No fix yet |
| Jul 9 | Red Hat GStreamer: buffer overflow | High7.1 | No fix yet |
| Jul 8 | Red Hat, Inc.: CVE records (CNA): denial of service | Medium6.5 | Red Hat+1 more |
| Jul 8 | Red Hat gorch service template: missing authentication | Medium6.3 | No fix yet |
| Jul 8 | Red Hat TrustyAI Service Operator.: information disclosure | Medium6.3 | No fix yet |
| Jul 8 | A flaw was found in 389 Directory Server | Low3.7 | No fix yet |