Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-19389— Gstreamer: gstreamer1-plugins-ugly-free: gstreamer: integer overflow/underflow in asfdemux bounds checks leading to out-of-bounds read

CVSS 7.1 · High EPSS 0.24% · P16

Affected Version Matrix 4

Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-19389

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Gstreamer: gstreamer1-plugins-ugly-free: gstreamer: integer overflow/underflow in asfdemux bounds checks leading to out-of-bounds read
Source: CVE Program / CVE List V5
Vulnerability Description
Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdemux) when parsing header objects from crafted ASF, WMV, or WMA files. Insufficient validation of attacker-controlled length and size values can bypass bounds checks and cause out-of-bounds heap reads. This can result in application crash, denial of service, or limited information disclosure when untrusted media is processed.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
整数溢出或超界折返
Source: CVE Program / CVE List V5
Vulnerability Title
GStreamer 数字错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
GStreamer是GStreamer组织开源的一个多媒体处理开发框架。 GStreamer存在数字错误漏洞,该漏洞源于解析特制的ASF、WMV或WMA文件中的标头对象时存在整数溢出和下溢,且对攻击者控制的长度和大小值验证不足,可绕过边界检查并导致越界堆读取,可能导致应用程序崩溃、拒绝服务或有限的信息泄露。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
Red HatRed Hat Enterprise Linux 10 0:1.26.7-2.el10_2.2 ~ * cpe:/o:redhat:enterprise_linux:10.2
Red HatRed Hat Enterprise Linux 7-cpe:/o:redhat:enterprise_linux:7
Red HatRed Hat Enterprise Linux 8-cpe:/o:redhat:enterprise_linux:8
Red HatRed Hat Enterprise Linux 9-cpe:/o:redhat:enterprise_linux:9

II. Public POCs for CVE-2026-19389

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-19389

登录查看更多情报信息。

Patches & Fixes for CVE-2026-19389 (1)

Vendor Advisories for CVE-2026-19389 (3)

Other References for CVE-2026-19389 (1)

Same Patch Batch · Red Hat · 2026-08-10 · 33 CVEs total

CVE-2026-189489.9 CRITICALFeast: feast: unsafe dill deserialization of registry-stored udfs — rce on feature server
CVE-2026-144509.9 CRITICALMaas-billing: maas api: privilege escalation via forged http headers due to missing authen
CVE-2026-189518.8 HIGHOdh-training-operator-rhel9: [trainer v2 security] trn-02: rhoai overlay aggregates trainj
CVE-2026-189508.8 HIGHOdh-dashboard: odh-dashboard: confused-deputy privilege escalation via unchecked roleref i
CVE-2026-189498.8 HIGHOdh-dashboard: odh-dashboard: clusterrole grants cluster-wide crud on secrets and rbac man
CVE-2026-189828.8 HIGHOdh-training-operator-rhel9: rhoai fork aggregates training job create onto native edit/ad
CVE-2026-186178.8 HIGHData-science-pipelines-operator: dspo: mysql dsn parameter injection via customextraparams
CVE-2026-137178.8 HIGHRhoai maas: llm-d: maas/llm-d inference gateway: default allowedroutes.namespaces.from: al
CVE-2026-186088.7 HIGHData-science-pipelines-operator: dspo: operator clusterrole grants pods/exec:*, kubeflow.o
CVE-2026-715768.5 HIGHMulticluster-global-hub: multicluster-global-hub: manager trusts self-asserted evt.source(
CVE-2026-189478.5 HIGHFeast: feast: authorization bypass in /materialize endpoints enables dos via unauthorized
CVE-2026-590908.4 HIGHGimp: gimp: arbitrary code execution in psd plugin due to unsigned underflow
CVE-2026-154678.1 HIGHTrustyai-service-operator: trustyai-service-operator: lmevaljob sidecar containers bypass
CVE-2026-155818.0 HIGHTrustyai-service-operator: trustyai-service-operator: tas internal service bypasses kube-r
CVE-2026-636227.8 HIGHLibvirt: swtpm privilege escalation via symlink following
CVE-2026-590877.8 HIGHGimp: heap buffer overflow in `file-seattle-filmworks` load — `fread` writes attacker-cont
CVE-2026-189417.7 HIGHFeast: feast-operator: feast: default authentication mode is no_auth — shared multi-tenant
CVE-2026-186217.6 HIGHData-sciences-pipeline: dsp: v1 argo template path accepts arbitrary workflow spec, bypass
CVE-2026-193877.6 HIGHGstreamer: gstreamer1-plugins-bad-free: gstreamer: heap out-of-bounds write in adpcmdec im
CVE-2026-186117.5 HIGHData-science-pipelines-operator: dspo: cryptographically weak secret generation (math/rand

Showing top 20 of 33 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2026-19389

No comments yet


Leave a comment