CVE-2026-52722
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
Summary
A signed integer overflow vulnerability was found in GStreamer's VMnc decoder. A crafted VMnc stream with large cursor dimensions can overflow signed integer payload-size arithmetic, bypassing a length check and leading to out-of-bounds reads. A remote attacker could trick a user into opening a specially crafted VMnc file, potentially causing a crash or information disclosure.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | 0:1.26.7-2.el10_2.4 < * | unaffected |
| Red Hat | Red Hat Enterprise Linux 10.0 Extended Update Support | 0:1.24.11-3.el10_0.4 < * | unaffected |
| Red Hat | Red Hat Enterprise Linux 7 Extended Lifecycle Support | 0:1.10.4-6.el7_9 < * | unaffected |
| Red Hat | Red Hat Enterprise Linux 7 Extended Lifecycle Support | 0:0.10.23-25.el7_9 < * | unaffected |
| Red Hat | Red Hat Enterprise Linux 8 | 0:1.16.1-8.el8_10 < * | unaffected |
| Red Hat | Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | 0:1.16.1-4.el8_4.2 < * | unaffected |
| Red Hat | Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | 0:1.16.1-4.el8_4.2 < * | unaffected |
| Red Hat | Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | 0:1.16.1-4.el8_6.2 < * | unaffected |
| Red Hat | Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On | 0:1.16.1-4.el8_6.2 < * | unaffected |
| Red Hat | Red Hat Enterprise Linux 8.8 Telecommunications Update Service | 0:1.16.1-4.el8_8.2 < * | unaffected |
| Red Hat | Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | 0:1.16.1-4.el8_8.2 < * | unaffected |
| Red Hat | Red Hat Enterprise Linux 9 | 0:1.22.12-7.el9_8.1 < * | unaffected |
| Red Hat | Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | 0:1.18.4-9.el9_2.3 < * | unaffected |
| Red Hat | Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions | 0:1.22.1-6.el9_4.4 < * | unaffected |
| Red Hat | Red Hat Enterprise Linux 9.6 Extended Update Support | 0:1.22.12-5.el9_6.4 < * | unaffected |
Weaknesses
- CWE-190: Integer Overflow or Wraparound
Workarounds
Red Hat is not aware of a practical temporary workaround that fully mitigates this issue or meets Red Hat Product Security's standards for usability, deployment, applicability, or stability. Customers are advised to apply the relevant security updates if they become available.
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: partial
gstreamer1-plugins-bad-free: GStreamer: Signed integer overflow in VMnc decoder cursor payload handling
Additional References
- https://access.redhat.com/security/cve/CVE-2026-52722
- https://bugzilla.redhat.com/show_bug.cgi?id=2486733
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-52722.json
- https://access.redhat.com/errata/RHSA-2026:49517
- https://access.redhat.com/errata/RHSA-2026:47176
- https://access.redhat.com/errata/RHSA-2026:47717
- https://access.redhat.com/errata/RHSA-2026:36749
- https://access.redhat.com/errata/RHSA-2026:37130
- https://access.redhat.com/errata/RHSA-2026:47076
- https://access.redhat.com/errata/RHSA-2026:47075
- https://access.redhat.com/errata/RHSA-2026:47718
- https://access.redhat.com/errata/RHSA-2026:47069
- https://access.redhat.com/errata/RHSA-2026:47071
- https://access.redhat.com/errata/RHSA-2026:47070
- https://access.redhat.com/errata/RHSA-2026:36834
References
- https://access.redhat.com/errata/RHSA-2026:36749
- https://access.redhat.com/errata/RHSA-2026:36834
- https://access.redhat.com/errata/RHSA-2026:37130
- https://access.redhat.com/errata/RHSA-2026:47069
- https://access.redhat.com/errata/RHSA-2026:47070
- https://access.redhat.com/errata/RHSA-2026:47071
- https://access.redhat.com/errata/RHSA-2026:47075
- https://access.redhat.com/errata/RHSA-2026:47076
- https://access.redhat.com/errata/RHSA-2026:47176
- https://access.redhat.com/errata/RHSA-2026:47717
- https://access.redhat.com/errata/RHSA-2026:47718
- https://access.redhat.com/errata/RHSA-2026:49517
- https://access.redhat.com/security/cve/CVE-2026-52722
- https://bugzilla.redhat.com/show_bug.cgi?id=2486733
- https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5107
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.