REDHAT-BUG-2513016: High severity GStreamer gst-plugins-ugly (asfdemux) vulnerability

Published Aug 10, 2026
·
Updated

A flaw was found in GStreamer gst-plugins-ugly (asfdemux). The ASF demuxer performed arithmetic on attacker-controlled length and size fields from ASF/WMV/WMA headers using 32-bit unsigned operations without adequate overflow and underflow checks. In gstasfdemuxprocessmetadata(), summing namelen and datalen could wrap, bypassing the available-data check and causing gconvert() to read beyond the heap buffer during UTF-16LE to UTF-8 conversion. Related underflow issues in other header parsers similarly produced oversized lengths and out-of-bounds reads. Because asfdemux is auto-plugged by playbin and decodebin, processing a crafted file can crash the application (denial of service) and may enable limited heap information disclosure via metadata handling. Fixed upstream in gst-plugins-ugly 1.28.6 (GStreamer-SA-2026-0075).

Affected Software

1 affected component
GStreamer gst-plugins-ugly (asfdemux)<1.28.6

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade GStreamer gst-plugins-ugly (asfdemux) to a version that resolves this vulnerability.

    Fixed in 1.28.6Patch GStreamer-SA-2026-0075

Event History

Aug 10, 2026
Data Sourced
via Red Hat·02:50 AM
DescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-2513016?

The severity of REDHAT-BUG-2513016 is rated as high with a score of 7.

2

What causes the vulnerability in REDHAT-BUG-2513016?

The vulnerability in REDHAT-BUG-2513016 is caused by improper handling of attacker-controlled length and size fields in ASF/WMV/WMA headers during arithmetic operations.

3

How can I mitigate the risks associated with REDHAT-BUG-2513016?

To mitigate the risks associated with REDHAT-BUG-2513016, users should update GStreamer gst-plugins-ugly to the latest patched version.

4

Which software is affected by REDHAT-BUG-2513016?

REDHAT-BUG-2513016 affects the GStreamer gst-plugins-ugly package, specifically the ASF demuxer.

5

What is the potential impact of exploiting REDHAT-BUG-2513016?

Exploiting REDHAT-BUG-2513016 could lead to potential crashes or execution of arbitrary code due to unchecked arithmetic operations.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203