REDHAT-BUG-2487613: Medium severity GStreamer GStreamer rmdemux (RealMedia demuxer) vulnerability

Published Jun 10, 2026
·
Updated

GStreamer RealMedia demuxer audio stream header OOB read. In gstrmdemuxparsemdpr(), audio header versions 4 and 5 read codec parameters at fixed byte offsets (22-69 for v4, 22-74 for v5) without bounds checking against the MDPR chunk length. OOB-read values control downstream buffer allocation, codec selection, and caps negotiation. No fix available; upstream recommends rmdemux rewrite. Reported via PSIRTSUPT-7239 by Tianshuo Han.

Affected Software

1 affected component
GStreamer GStreamer rmdemux (RealMedia demuxer)

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Compensating control

    Mitigate the GStreamer RealMedia demuxer OOB read (PSIRTSUPT-7239) by avoiding RealMedia streams that require gst_rmdemux_parse_mdpr() until rmdemux is rewritten upstream; block/disable RealMedia (RealAudio/RealMedia) demuxing in your media pipeline where applicable.

  2. Operational

    If RealMedia content may have been processed, review and harden downstream handling of caps/codec selection and buffer allocation to ensure OOB-influenced values from malformed streams cannot cause unsafe allocations (e.g., apply strict caps validation and bounds checks before using negotiated values).

Event History

Jun 10, 2026
Data Sourced
via Red Hat·04:14 PM
DescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-2487613?

The severity of REDHAT-BUG-2487613 is medium, rated at 4.

2

What type of vulnerability is REDHAT-BUG-2487613?

REDHAT-BUG-2487613 is an out-of-bounds read vulnerability in the GStreamer RealMedia demuxer.

3

How do I fix REDHAT-BUG-2487613?

To fix REDHAT-BUG-2487613, update your GStreamer package to the latest version addressing this vulnerability.

4

What is the impact of REDHAT-BUG-2487613?

The impact of REDHAT-BUG-2487613 includes potential uncontrolled memory access leading to application crashes or exploitation.

5

When was REDHAT-BUG-2487613 published?

REDHAT-BUG-2487613 was published on June 10, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203