GStreamer gst-plugins-good contains a vulnerability in the MOV/MP4 demuxer (qtdemux) closed-caption parser. In the extractccfromdata() function in subprojects/gst-plugins-good/gst/isomp4/qtdemux.c, when parsing a CEA-608 caption sample containing two atoms (cdat/cdt2), the bounds check for the second atom at line 6426 computes 'atomlength + newatomlength' using 32-bit unsigned arithmetic (both are guint32). An attacker can craft the second atom's length (newatomlength) such that this addition wraps around to a small value, bypassing the bounds check. The value 'newatomlength - 8' is then passed to converttos3341a() as a guint8 parameter (ccpairsize), truncating a large 32-bit value to at most 244 bytes. This causes converttos3341a() to read up to 244 bytes beyond the valid caption sample buffer, and the out-of-bounds heap data is included in the downstream caption output stream. Versions prior to gst-plugins-good 1.28.7 are affected. Fixed in gst-plugins-good 1.28.7. Security Advisory: GStreamer-SA-2026-0079. Upstream MR: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/mergerequests/12433. Reported by Seonwook Kim. PSIRT ticket: PSIRTSUPT-23503.
A 4-byte heap-buffer-overflow (out-of-bounds read) was found in gst-plugins-good's Matroska demuxer, in the function gstmatroskaparseflacstreamheaders() in gst/matroska/matroska-ids.c. When parsing FLAC codec private data embedded in a Matroska (MKV/WebM) container, the function iterates over FLAC metadata blocks. Each block has a 4-byte header (1 byte flags + 3 bytes length) followed by a body of 'len' bytes. The bounds check at line 309 validates 'off + len > codecdatasize' but the subsequent gstbuffernewmemdup() at line 314 copies 'len + 4' bytes (body + header). When off + len == codecdatasize, the guard passes but the memdup reads 4 bytes past the end of the heap-allocated codecdata buffer. The correct check should be 'off + 4 + len > codecdatasize'. This function is called from matroska-demux.c line 7397 when processing AFLAC audio tracks.
Affected versions: <= 1.28.5 Fixed in version: 1.28.6 (upcoming) Fix MR: https://gitlab.freedesktop.org/gstreamer/gstreamer-security/-/mergerequests/111 (GST-SA-2026-0073) Reporter: Yazan Balawneh, CyStack Security Team ASan confirmation on GStreamer 1.28.4, Kali Linux x8664: heap-buffer-overflow READ of size 42, 0 bytes after 42-byte region. PSIRT Ticket: PSIRTSUPT-19737
An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's qtdemuxaudiocaps function does not sufficiently validate atom data before performing division operations, leading to denial of service due to integer division by zero.
An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's qtdemuxparsetrak function does not sufficiently validate atom data before performing division operations, leading to denial of service due to integer division by zero.