CVE-2021-3497: Use After Free
GStreamer before 1.18.4 might access already-freed memory in error code paths when demuxing certain malformed Matroska files.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/gst-plugins-good1.0to a version that resolves this vulnerability.Fixed in 1.14.4-1+deb10u1Fixed in 1.14.4-1+deb10u3Fixed in 1.18.4-2+deb11u2Fixed in 1.22.0-5+deb12u1Fixed in 1.22.6-1 - Upgrade
Upgrade
redhat/gstreamer-plugins-goodto a version that resolves this vulnerability.Fixed in 1.18.4 - Upgrade
Upgrade
gstreamerto a version that resolves this vulnerability.Fixed in 1.18.4Patch sa-2021-0002
Event History
Frequently Asked Questions
What is CVE-2021-3497?
CVE-2021-3497 is a vulnerability in GStreamer before version 1.18.4 that could allow an attacker to access already-freed memory in error code paths when demuxing certain malformed Matroska files.
How does CVE-2021-3497 impact GStreamer?
CVE-2021-3497 affects GStreamer versions before 1.18.4, potentially leading to the exploitation of already-freed memory.
What is the severity of CVE-2021-3497?
CVE-2021-3497 has a severity score of 7.8 out of 10 (high).
Which software versions are affected by CVE-2021-3497?
GStreamer versions before 1.18.4, Debian Linux 9.0 and 10.0, Redhat Enterprise Linux 7.0 and 8.0, and gst-plugins-good1.0 in certain Debian packages are affected.
How can I fix CVE-2021-3497?
To fix CVE-2021-3497, update GStreamer to version 1.18.4 or later, or apply the provided patches in the affected Debian packages.