CVE-2026-73433: Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd parsing leading to out-of-bounds read/write

Published Aug 12, 2026
·
Updated

A flaw was found in GStreamer gst-plugins-good (avidemux). When parsing FUJIFILM metadata in an AVI strd chunk, gstavidemuxparsestrd() decrements a remaining-length counter by fixed offsets (98 and 10 bytes) without verifying sufficient data remains. For crafted strd payloads of exactly 106 or 107 bytes, the counter underflows to a very large unsigned value, causing subsequent null-terminated string scanning to read far beyond the allocated heap buffer. Date-format normalization may also write beyond the buffer end. Confirmed impacts include heap out-of-bounds read, out-of-bounds write, heap information disclosure (adjacent data appearing in parsed metadata), and application crash/denial of service. The avidemux element is auto-plugged by playbin, decodebin, and gst-discoverer, so opening or previewing a crafted AVI is sufficient to trigger the issue. Fixed upstream in gst-plugins-good 1.28.6 (GStreamer-SA-2026-0072).

Other sources

The CVE was requested in this ticket: https://redhat.atlassian.net/browse/PSIRTSUPT-20037 (Also received as resubmission: https://redhat.atlassian.net/browse/PSIRTSUPT-21422)

Reserved the following CVE ID(s): CVE-2026-73433 ├─ State: RESERVED ├─ Owning CNA: redhat ├─ Reserved by: ctimko (redhat) └─ Reserved on: Wed Aug 12 16:14:17 2026 +0000

Red Hat

Affected Software

1 affected component
gstreamer1-plugins-good<1.28.6

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade gst-plugins-good (avidemux) to a version that resolves this vulnerability.

    Fixed in 1.28.6Patch GStreamer-SA-2026-0072
  2. Compensating control

    Avoid opening or previewing crafted AVI files that contain FUJIFILM metadata in an AVI strd chunk, since the avidemux element is auto-plugged by playbin, decodebin, and gst-discoverer and parsing FUJIFILM strd payloads can trigger the issue.

Event History

Aug 12, 2026
Data Sourced
via Red Hat·04:20 PM
DescriptionSeverityAffected Software
CVE Published
via MITRE·07:05 PM
Data Sourced
via MITRE·07:05 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-73433?

CVE-2026-73433 has a severity score of 7.6, rated as high.

2

How do I fix CVE-2026-73433?

To fix CVE-2026-73433, update to the latest version of gstreamer1-plugins-good where the vulnerability has been patched.

3

What types of attacks are possible with CVE-2026-73433?

CVE-2026-73433 could allow an attacker to execute out-of-bounds read/write operations through crafted FUJIFILM metadata.

4

What software is affected by CVE-2026-73433?

CVE-2026-73433 affects the gstreamer1-plugins-good package.

5

What does CVE-2026-73433 exploit in the gstreamer software?

CVE-2026-73433 exploits an unsigned integer underflow in the parsing of FUJIFILM metadata in AVI strd chunks.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203