在 GStreamer 的 RTSP 支持库中发现了一个空指针解引用缺陷。该漏洞发生在解析使用 Digest 认证机制的 Authorization 或 WWW-Authenticate 头部时。如果参数终止符周围的空格位置经过特殊构造,会导致内部长度计算发生下溢,从而引发解析该头部的进程崩溃。在启用认证的 RTSP 服务器上,远程未认证的攻击者可以通过发送一个构造不当的请求来触发此漏洞;同样的缺陷也可能由恶意或已被攻陷的 RTSP 服务器针对 RTSP 客户端触发。成功利用该漏洞将导致服务拒绝(应用崩溃),但目前
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 7 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 8 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 9 | any |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-71221 | 7.0 HIGH | Gfs2-utils: gfs2-utils: stack out-of-bounds write via unchecked height in savemeta |
| CVE-2026-71220 | 7.0 HIGH | Gfs2-utils: gfs2-utils: stack out-of-bounds write via unchecked di_height in gfs2_edit |
| CVE-2026-84185 | 5.9 MEDIUM | Jwcrypto: jwcrypto: general json jws kid binding bypass during jwkset verification |
| CVE-2026-71222 | 5.3 MEDIUM | Gfs2-utils: gfs2-utils: heap out-of-bounds read via unchecked ea_num_ptrs in extended attr |
| CVE-2026-71224 | 4.7 MEDIUM | Gfs2-utils: gfs2-utils: stack overflow via alloca(i_height) in metadata walk |
| CVE-2026-71219 | 4.7 MEDIUM | Gfs2-utils: gfs2-utils: stack overflow via alloca(1<<di_depth) in hash table traversal |
No comments yet