gst-plugins-bad是GStreamer开源的一个GStreamer插件。 gst-plugins-bad存在缓冲区错误漏洞,该漏洞源于H.265编解码器解析器库在解析缓冲期SEI消息时使用错误的循环边界,导致写入栈分配的CPB延迟数组边界之外,精心构造的H.265视频文件或流可能导致崩溃或栈内存损坏。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 7 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 8 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 9 | any |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-11774 | 7.6 HIGH | 389-ds-base: 389-ds-base: integer overflow in sasl packet length bypasses size limit leadi |
| CVE-2026-53701 | 6.5 MEDIUM | Gstreamer1-plugins-bad-free: gstreamer: out-of-bounds write in h.266/vvc pps picture parti |
| CVE-2026-11850 | 5.0 MEDIUM | Krb5: krb5: integer underflow in berval2tl_data() leads to heap out-of-bounds read |
| CVE-2026-11986 | 4.9 MEDIUM | Keycloak-rest-admin-ui-ext: authorization bypass vulnerability in the admin-ui-ext bulk ro |
No comments yet