Security Advisory 2026-0008 (CVE-2026-3083, CVE-2026-3085, ZDI-CAN-28851, ZDI-CAN-28850)
|
|
| Summary |
Multiple vulnerabilities in RTP QDM2 depayloader element |
| Date |
2026-02-25 |
| Affected Versions |
GStreamer gst-plugins-good 1.28 < 1.28.1, 1.x <= 1.26.10 |
| IDs |
GStreamer-SA-2026-0008 CVE-2026-3083 CVE-2026-3085 ZDI-CAN-28851 ZDI-CAN-28850 |
Details
Heap-based buffer overflow and out-of-bounds write in the RTP QDM2 depayloader.
Impact
It is possible for a malicious third party to trigger a heap overflow or
out-of-bounds write that can result in a crash of the application, possibly
even remote execution.
Solution
The gst-plugins-good 1.28.1 release addresses the issue by disabling the
RTP QDM2 depayloader element entirely. QDM2 was a streaming format produced
by Darwin Streaming Server around 2009 that has not been in active use for
well over a decade. The element should not be used. Future releases of
GStreamer will remove it completely.
People using older versions of GStreamer should apply the patch and recompile,
or disable the element to mitigate the vulnerability.
References
The GStreamer project
CVE Database Entries
GStreamer releases
1.28 (current stable)
Patches