CVE-2026-59692

Summary

A stack buffer overflow vulnerability was found in GStreamer's DTLS plugin. During a DTLS handshake, the peer certificate Subject Distinguished Name is printed into a fixed-size 2048-byte stack buffer without bounds checking. A remote unauthenticated attacker can send a certificate with an oversized Subject DN that exceeds the buffer, causing a stack buffer overflow and process crash, resulting in denial of service.

Affected Software

VendorProductVersion RangeStatus
Red HatRed Hat Enterprise Linux 100:1.26.7-2.el10_2.6 < *unaffected
Red HatRed Hat Enterprise Linux 10.0 Extended Update Support0:1.24.11-3.el10_0.6 < *unaffected
Red HatRed Hat Enterprise Linux 7 Extended Lifecycle Support0:1.10.4-7.el7_9 < *unaffected
Red HatRed Hat Enterprise Linux 80:1.16.1-9.el8_10.1 < *unaffected
Red HatRed Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support0:1.16.1-4.el8_4.4 < *unaffected
Red HatRed Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On0:1.16.1-4.el8_4.4 < *unaffected
Red HatRed Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support0:1.16.1-4.el8_6.4 < *unaffected
Red HatRed Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On0:1.16.1-4.el8_6.4 < *unaffected
Red HatRed Hat Enterprise Linux 8.8 Telecommunications Update Service0:1.16.1-4.el8_8.4 < *unaffected
Red HatRed Hat Enterprise Linux 8.8 Update Services for SAP Solutions0:1.16.1-4.el8_8.4 < *unaffected
Red HatRed Hat Enterprise Linux 90:1.22.12-7.el9_8.3 < *unaffected
Red HatRed Hat Enterprise Linux 9.2 Update Services for SAP Solutions0:1.18.4-9.el9_2.5 < *unaffected
Red HatRed Hat Enterprise Linux 9.4 Update Services for SAP Solutions0:1.22.1-6.el9_4.6 < *unaffected
Red HatRed Hat Enterprise Linux 9.6 Extended Update Support0:1.22.12-5.el9_6.6 < *unaffected

Weaknesses

  • CWE-121: Stack-based Buffer Overflow

Workarounds

There is no complete mitigation for this vulnerability. The following measures can reduce risk:

  1. If WebRTC/DTLS functionality is not required, remove the DTLS plugin shared object from the GStreamer plugins directory (typically /usr/lib64/gstreamer-1.0/libgstdtls.so).
  2. Restrict network access to WebRTC/DTLS endpoints to trusted peers only via firewall rules.
  3. Deploy GStreamer WebRTC services behind a reverse proxy or media server that validates DTLS certificates before forwarding.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References