CVE-2026-53702

Public on 2026-06-11
Modified on 2026-06-12
Description
A stack buffer overflow flaw was found in the GStreamer H.265 codec parser library (gst-plugins-bad). When parsing a buffering period SEI message, the parser uses an incorrect loop bound derived from cpb_cnt_minus1[i] (the loop index) instead of the sub-layer 0 CPB count cpb_cnt_minus1[0] from the referenced Sequence Parameter Set. A crafted H.265 video file or stream can cause the parser to write beyond the bounds of stack-allocated CPB delay arrays, resulting in a crash or potential stack memory corruption.
Severity
Medium severity
Medium
See what this means
CVSS v3 Base Score
5.5
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Core gstreamer-plugins-bad-free Not Affected
Amazon Linux 2 - Core gstreamer1-plugins-bad-free Pending Fix
Amazon Linux 2023 gstreamer1-plugins-bad-free Pending Fix
Amazon Linux 2 - Core gtk2 Not Affected
Amazon Linux 2 - Core gtk3 Not Affected
Amazon Linux 2023 gtk3 Not Affected
Amazon Linux 2023 gtk4 Not Affected

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H