REDHAT-BUG-2491318: Buffer Overflow
A global buffer overflow (out-of-bounds read) was found in GStreamer's gst-plugins-bad H.266/VVC parser in the gsth266parsevuiparameters() function at subprojects/gst-plugins-bad/gst-libs/gst/codecparsers/gsth266parser.c:561. The aspectratioidc field is read as an 8-bit value (0-255) from the H.266 bitstream and used directly as an array index into the aspectratios[] array, which contains only 17 entries (indices 0-16). When aspectratioidc is 17-254, the code performs an 8-byte out-of-bounds read from the .data section (reading two guint fields: parn and pard). The H.265 parser (gsth265parser.c) contains the correct bounds check (else if (vui->aspectratioidc <= 16)) which is missing in the H.266 implementation, indicating this was an oversight during porting. The leaked values are stored in GstH266VUIParams and propagated to GStreamer caps as pixel-aspect-ratio metadata, affecting video scaling in downstream components. Upstream maintainer Sebastian Dröge confirmed the vulnerability is valid and that the proposed patch is correct. The bug affects all versions containing the H.266 parser. Reported by Dr. Faruk Kazi and Ramesh Adhikari from CoE-CNDS Lab, VJTI, Mumbai, India. Upstream tracking: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/workitems/5109
PSIRT Ticket: PSIRTSUPT-17586
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GStreamer gst-plugins-bad H.266/VVC parser (gst_h266_parse_vui_parameters)to a version that resolves this vulnerability.Patch PSIRTSUPT-17586 - Configuration
In gst_h266_parse_vui_parameters() (subprojects/gst-plugins-bad/gst-libs/gst/codecparsers/gsth266parser.c:561), add the missing bounds check before indexing aspect_ratios[] (17 entries, indices 0-16). Specifically, prevent the direct use of 8-bit aspect_ratio_idc (0-255) when it is 17-254 to stop the 8-byte out-of-bounds read from .data and the propagation of leaked values to Gst caps as pixel-aspect-ratio metadata.
GStreamer gst-plugins-bad H.266/VVC parser (gsth266parser.c) aspect_ratio_idc bounds check for aspect_ratios[] array indexing = Add/restore conditional check so vui->aspect_ratio_idc is only used as an index when vui->aspect_ratio_idc <= 16 (matching the existing H.265 logic shown as else if (vui->aspect_ratio_idc <= 16)).
Event History
Frequently Asked Questions
Which systems are exposed?
Any deployment using a GStreamer gst-plugins-bad build that contains the H.266/VVC parser is affected. The issue applies to all versions containing that parser.
What must an attacker provide to trigger the issue?
The attacker needs to cause the parser to process an H.266 bitstream whose VUI aspect_ratio_idc value is between 17 and 254. That value is used as an unchecked index into an array with only 17 entries.
What is the observable impact of successful exploitation?
The parser performs an 8-byte out-of-bounds read, obtaining two guint values from the data section. Those values are stored as pixel-aspect-ratio metadata and can affect video scaling in downstream components.
How can I determine whether my deployment is affected?
Determine whether the installed GStreamer gst-plugins-bad component includes the H.266/VVC parser. If it does, the affected code is present regardless of version, based on the available information.