REDHAT-BUG-2491318: Buffer Overflow

Published Jun 22, 2026
·
Updated

A global buffer overflow (out-of-bounds read) was found in GStreamer's gst-plugins-bad H.266/VVC parser in the gsth266parsevuiparameters() function at subprojects/gst-plugins-bad/gst-libs/gst/codecparsers/gsth266parser.c:561. The aspectratioidc field is read as an 8-bit value (0-255) from the H.266 bitstream and used directly as an array index into the aspectratios[] array, which contains only 17 entries (indices 0-16). When aspectratioidc is 17-254, the code performs an 8-byte out-of-bounds read from the .data section (reading two guint fields: parn and pard). The H.265 parser (gsth265parser.c) contains the correct bounds check (else if (vui->aspectratioidc <= 16)) which is missing in the H.266 implementation, indicating this was an oversight during porting. The leaked values are stored in GstH266VUIParams and propagated to GStreamer caps as pixel-aspect-ratio metadata, affecting video scaling in downstream components. Upstream maintainer Sebastian Dröge confirmed the vulnerability is valid and that the proposed patch is correct. The bug affects all versions containing the H.266 parser. Reported by Dr. Faruk Kazi and Ramesh Adhikari from CoE-CNDS Lab, VJTI, Mumbai, India. Upstream tracking: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/workitems/5109

PSIRT Ticket: PSIRTSUPT-17586

Affected Software

1 affected component
GStreamer gst-plugins-bad

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade GStreamer gst-plugins-bad H.266/VVC parser (gst_h266_parse_vui_parameters) to a version that resolves this vulnerability.

    Patch PSIRTSUPT-17586
  2. Configuration

    In gst_h266_parse_vui_parameters() (subprojects/gst-plugins-bad/gst-libs/gst/codecparsers/gsth266parser.c:561), add the missing bounds check before indexing aspect_ratios[] (17 entries, indices 0-16). Specifically, prevent the direct use of 8-bit aspect_ratio_idc (0-255) when it is 17-254 to stop the 8-byte out-of-bounds read from .data and the propagation of leaked values to Gst caps as pixel-aspect-ratio metadata.

    GStreamer gst-plugins-bad H.266/VVC parser (gsth266parser.c) aspect_ratio_idc bounds check for aspect_ratios[] array indexing = Add/restore conditional check so vui->aspect_ratio_idc is only used as an index when vui->aspect_ratio_idc <= 16 (matching the existing H.265 logic shown as else if (vui->aspect_ratio_idc <= 16)).

Event History

Jun 22, 2026
Data Sourced
via Red Hat·11:15 AM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

Which systems are exposed?

Any deployment using a GStreamer gst-plugins-bad build that contains the H.266/VVC parser is affected. The issue applies to all versions containing that parser.

2

What must an attacker provide to trigger the issue?

The attacker needs to cause the parser to process an H.266 bitstream whose VUI aspect_ratio_idc value is between 17 and 254. That value is used as an unchecked index into an array with only 17 entries.

3

What is the observable impact of successful exploitation?

The parser performs an 8-byte out-of-bounds read, obtaining two guint values from the data section. Those values are stored as pixel-aspect-ratio metadata and can affect video scaling in downstream components.

4

How can I determine whether my deployment is affected?

Determine whether the installed GStreamer gst-plugins-bad component includes the H.266/VVC parser. If it does, the affected code is present regardless of version, based on the available information.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203