CVE-2026-52722

Summary

A signed integer overflow vulnerability was found in GStreamer's VMnc decoder. A crafted VMnc stream with large cursor dimensions can overflow signed integer payload-size arithmetic, bypassing a length check and leading to out-of-bounds reads. A remote attacker could trick a user into opening a specially crafted VMnc file, potentially causing a crash or information disclosure.

Affected Software

VendorProductVersion RangeStatus
Red HatRed Hat Enterprise Linux 100:1.26.7-2.el10_2.4 < *unaffected
Red HatRed Hat Enterprise Linux 10.0 Extended Update Support0:1.24.11-3.el10_0.4 < *unaffected
Red HatRed Hat Enterprise Linux 7 Extended Lifecycle Support0:1.10.4-6.el7_9 < *unaffected
Red HatRed Hat Enterprise Linux 7 Extended Lifecycle Support0:0.10.23-25.el7_9 < *unaffected
Red HatRed Hat Enterprise Linux 80:1.16.1-8.el8_10 < *unaffected
Red HatRed Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support0:1.16.1-4.el8_4.2 < *unaffected
Red HatRed Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On0:1.16.1-4.el8_4.2 < *unaffected
Red HatRed Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support0:1.16.1-4.el8_6.2 < *unaffected
Red HatRed Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On0:1.16.1-4.el8_6.2 < *unaffected
Red HatRed Hat Enterprise Linux 8.8 Telecommunications Update Service0:1.16.1-4.el8_8.2 < *unaffected
Red HatRed Hat Enterprise Linux 8.8 Update Services for SAP Solutions0:1.16.1-4.el8_8.2 < *unaffected
Red HatRed Hat Enterprise Linux 90:1.22.12-7.el9_8.1 < *unaffected
Red HatRed Hat Enterprise Linux 9.2 Update Services for SAP Solutions0:1.18.4-9.el9_2.3 < *unaffected
Red HatRed Hat Enterprise Linux 9.4 Update Services for SAP Solutions0:1.22.1-6.el9_4.4 < *unaffected
Red HatRed Hat Enterprise Linux 9.6 Extended Update Support0:1.22.12-5.el9_6.4 < *unaffected

Weaknesses

  • CWE-190: Integer Overflow or Wraparound

Workarounds

Red Hat is not aware of a practical temporary workaround that fully mitigates this issue or meets Red Hat Product Security's standards for usability, deployment, applicability, or stability. Customers are advised to apply the relevant security updates if they become available.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

gstreamer1-plugins-bad-free: GStreamer: Signed integer overflow in VMnc decoder cursor payload handling

Additional References

References