CVE-2026-39043

Public on 2026-06-19
Modified on 2026-06-19
Description
Heap buffer overflow in the Matroska (MKV) demuxer when calculating decompressed buffer sizes for bz2-compressed tracks. The issue occurs due to missing parentheses in the buffer size calculation, causing incorrect memory allocation and potential out-of-bounds writes. (from https://gstreamer.freedesktop.org/security/sa-2026-0022.html)
Severity
Important severity
Important
See what this means
CVSS v3 Base Score
7.8
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Core gstreamer-plugins-good Not Affected
Amazon Linux 2 - Core gstreamer1-plugins-good Pending Fix
Amazon Linux 2023 gstreamer1-plugins-good Pending Fix

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H