REDHAT-BUG-2487611: Medium severity GStreamer GStreamer vulnerability
Published Jun 10, 2026
·Updated
GStreamer H.266/VVC PPS picture partition parser out-of-bounds write. In gsth266parserparsepicturepartition(), the multi-slice-in-tile loop writes past fixed-size arrays without bounds checking. Fixed in GStreamer 1.28.3 (commit f66e8292ed, MR !11581). Reported via PSIRTSUPT-7239 by Tianshuo Han.
Affected Software
1 affected component
GStreamer GStreamer<1.28.3
Event History
Jun 10, 2026
Data Sourced
via Red Hat·04:11 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2487611?
The severity of REDHAT-BUG-2487611 is classified as medium with a score of 4.
2
What type of vulnerability is REDHAT-BUG-2487611?
REDHAT-BUG-2487611 is an out-of-bounds write vulnerability in the GStreamer H.266/VVC PPS picture partition parser.
3
How do I fix REDHAT-BUG-2487611?
To fix REDHAT-BUG-2487611, upgrade to GStreamer version 1.28.3 or later.
4
Which function is affected by REDHAT-BUG-2487611?
The function affected by REDHAT-BUG-2487611 is gst_h266_parser_parse_picture_partition().
5
When was REDHAT-BUG-2487611 published?
REDHAT-BUG-2487611 was published on June 10, 2026.