CVE-2026-18649

🟡 Monitoruj

Brak limitu rozmiaru bufora w GStreamer pozwala na atak typu denial of service.

CVSS
7.5
EPSS
0.9%
Exploit
none
Vendor
Opis źródłowy (NVD)

A flaw was found in the GStreamer gst-plugins-good package. The rtph264depay and rtph265depay RTP depayloader elements do not enforce a maximum size limit on the reassembly buffer used during fragmented RTP packet processing. A remote, unauthenticated attacker can send a continuous stream of RTP fragments without ever transmitting an end-of-fragment marker, causing the reassembly buffer to grow without bound until process memory is exhausted. This results in a denial of service through process termination.

dos Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS7.5
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.9%
Opublikowano (NVD)2026-08-06 08:16:29 UTC
Ostatnia modyfikacja (NVD)2026-09-17 18:16:38 UTC
Referencje