CVE-2026-19387

Public on 2026-08-10
Modified on 2026-08-10
Description
A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio. Insufficient validation of the per-block sample count for multi-channel streams allows a crafted WAV file to cause writes beyond the allocated output buffer. This can lead to application crash, denial of service, memory corruption, or potentially arbitrary code execution when untrusted media is processed.
Severity
Important severity
Important
See what this means
CVSS v3 Base Score
7.1
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Core gstreamer-plugins-bad-free 2026-08-31 ALAS2-2026-3896 Fixed
Amazon Linux 2 - Core gstreamer1-plugins-bad-free 2026-08-31 ALAS2-2026-3895 Fixed
Amazon Linux 2023 gstreamer1-plugins-bad-free 2026-08-31 ALAS2023-2026-2119 Fixed

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H