Skip to content
Red HatCVE-2026-85150

Red Hat Enterprise Linux 7: null pointer dereference

High7.5CVE-2026-85150 · Published Sep 3, 2026 · updated Sep 21, 2026

A NULL pointer dereference flaw was found in GStreamer's RTSP support library. The vulnerability occurs while parsing an Authorization or WWW-Authenticate header that uses Digest authentication. Specially crafted whitespace placement around a parameter's terminator can cause an internal length calculation to underflow, leading to a crash of the process parsing the header. On an RTSP server this can be triggered by a remote, unauthenticated attacker sending a single malformed request when the server has authentication enabled; the same flaw can also be triggered against an RTSP client by a malicious or compromised RTSP server. Successful exploitation results in a denial of service (application crash) and has no confirmed impact on confidentiality or integrity.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat Enterprise Linux 7
Product
all versionsNo fix yet
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat Ansible Automation Platform 2: improper signature check
Medium5.9Sep 3
Red Hat gfs2-utils: out-of-bounds read
Medium5.3Sep 3
Red Hat gfs2-utils. The metadata walk code: denial of service
Medium4.7Sep 3
Red Hat gfs2-utils. The hash table traversal code: denial of service
Medium4.7Sep 3
Red Hat gfs2-utils.: out-of-bounds write
High7.0Sep 3
Red Hat gfs2-utils.: out-of-bounds write
High7.0Sep 3

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.