GStreamer是GStreamer组织开源的一个多媒体处理开发框架。 GStreamer存在缓冲区错误漏洞,该漏洞源于GStreamer gst-plugins-bad的adpcmdec元素在解码IMA/DVI ADPCM音频时对多声道流的每块样本数验证不足,特制的WAV文件可能导致超出分配输出缓冲区的写入,从而造成应用程序崩溃、拒绝服务、内存损坏或任意代码执行。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | 0:1.26.7-2.el10_2.7< * |
unaffected |
| Red Hat | Red Hat Enterprise Linux 7 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 8 | 0:1.16.1-9.el8_10.2< * |
unaffected |
| Red Hat | Red Hat Enterprise Linux 9 | 0:1.22.12-7.el9_8.4< * |
unaffected |
0:1.22.12-6.el9_8.2< * |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | 0:1.26.7-2.el10_2.7 ~ * |
cpe:/o:redhat:enterprise_linux:10.2
|
|
| Red Hat | Red Hat Enterprise Linux 8 | 0:1.16.1-9.el8_10.2 ~ * |
cpe:/a:redhat:enterprise_linux:8::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 9 | 0:1.22.12-7.el9_8.4 ~ * |
cpe:/a:redhat:enterprise_linux:9::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 9 | 0:1.22.12-6.el9_8.2 ~ * |
cpe:/a:redhat:enterprise_linux:9::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-18948 | 9.9 CRITICAL | Feast: feast: unsafe dill deserialization of registry-stored udfs — rce on feature server |
| CVE-2026-14450 | 9.9 CRITICAL | Maas-billing: maas api: privilege escalation via forged http headers due to missing authen |
| CVE-2026-18982 | 8.8 HIGH | Odh-training-operator-rhel9: rhoai fork aggregates training job create onto native edit/ad |
| CVE-2026-18951 | 8.8 HIGH | Odh-training-operator-rhel9: [trainer v2 security] trn-02: rhoai overlay aggregates trainj |
| CVE-2026-18950 | 8.8 HIGH | Odh-dashboard: odh-dashboard: confused-deputy privilege escalation via unchecked roleref i |
| CVE-2026-18949 | 8.8 HIGH | Odh-dashboard: odh-dashboard: clusterrole grants cluster-wide crud on secrets and rbac man |
| CVE-2026-13717 | 8.8 HIGH | Rhoai maas: llm-d: maas/llm-d inference gateway: default allowedroutes.namespaces.from: al |
| CVE-2026-18617 | 8.8 HIGH | Data-science-pipelines-operator: dspo: mysql dsn parameter injection via customextraparams |
| CVE-2026-18608 | 8.7 HIGH | Data-science-pipelines-operator: dspo: operator clusterrole grants pods/exec:*, kubeflow.o |
| CVE-2026-18947 | 8.5 HIGH | Feast: feast: authorization bypass in /materialize endpoints enables dos via unauthorized |
| CVE-2026-71576 | 8.5 HIGH | Multicluster-global-hub: multicluster-global-hub: manager trusts self-asserted evt.source( |
| CVE-2026-15467 | 8.1 HIGH | Trustyai-service-operator: trustyai-service-operator: lmevaljob sidecar containers bypass |
| CVE-2026-15581 | 8.0 HIGH | Trustyai-service-operator: trustyai-service-operator: tas internal service bypasses kube-r |
| CVE-2026-63622 | 7.8 HIGH | Libvirt: swtpm privilege escalation via symlink following |
| CVE-2026-18941 | 7.7 HIGH | Feast: feast-operator: feast: default authentication mode is no_auth — shared multi-tenant |
| CVE-2026-18621 | 7.6 HIGH | Data-sciences-pipeline: dsp: v1 argo template path accepts arbitrary workflow spec, bypass |
| CVE-2026-18611 | 7.5 HIGH | Data-science-pipelines-operator: dspo: cryptographically weak secret generation (math/rand |
| CVE-2026-18618 | 7.5 HIGH | Ml-metdata: bundled grpc 1.46.3 (2022) with published http/2 dos cves — directly reachable |
| CVE-2026-18620 | 7.1 HIGH | Data-sciences-pipeline: user-controlled serviceaccount for workflow pods without authoriza |
| CVE-2026-19389 | 7.1 HIGH | Gstreamer: gstreamer1-plugins-ugly-free: gstreamer: integer overflow/underflow in asfdemux |
Showing top 20 of 29 CVEs. View all on vendor page → →
No comments yet