CVE-2026-19387
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H
Summary
A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio. Insufficient validation of the per-block sample count for multi-channel streams allows a crafted WAV file to cause writes beyond the allocated output buffer. This can lead to application crash, denial of service, memory corruption, or potentially arbitrary code execution when untrusted media is processed.
Affected Software
| Vendor | Product | Version Range | Status |
|---|
Weaknesses
- CWE-787: Out-of-bounds Write
Workarounds
To mitigate this issue, users should avoid playing or processing untrusted multi-channel IMA ADPCM WAV files. Additionally, consider sandboxing applications that handle untrusted media to limit the potential impact of exploitation.
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: partial
References
- https://access.redhat.com/security/cve/CVE-2026-19387
- https://bugzilla.redhat.com/show_bug.cgi?id=2513015
- https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12235
- https://gstreamer.freedesktop.org/releases/1.28/
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.