Impact
A use‑after‑free flaw in the GStreamer rtpsbcdepay component allows an attacker to execute arbitrary code within the context of a process that loads the library. The vulnerability arises when the code fails to validate the existence of an object before performing operations on it. Because the flaw only requires interaction with the library, an attacker who can supply crafted RTP payloads can potentially take full control of the application and any privileges it holds.
Affected Systems
All installations of GStreamer that include the rtpsbcdepay module are at risk. The advisory does not specify exact version numbers, so any deployment using GStreamer should be evaluated for the presence of this component and updated if a patch is available.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity. The EPSS score is not provided, so the precise likelihood of exploitation is unknown. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is the delivery of a malicious RTP payload over a network connection that exposes rtpsbcdepay to untrusted traffic, which can trigger the use‑after‑free condition and allow code execution.
OpenCVE Enrichment