Description
GStreamer rtpsbcdepay Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation.

The specific flaw exists within the processing of RTP payload elements. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29787.
Published: 2026-08-20
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A use‑after‑free flaw in the GStreamer rtpsbcdepay component allows an attacker to execute arbitrary code within the context of a process that loads the library. The vulnerability arises when the code fails to validate the existence of an object before performing operations on it. Because the flaw only requires interaction with the library, an attacker who can supply crafted RTP payloads can potentially take full control of the application and any privileges it holds.

Affected Systems

All installations of GStreamer that include the rtpsbcdepay module are at risk. The advisory does not specify exact version numbers, so any deployment using GStreamer should be evaluated for the presence of this component and updated if a patch is available.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity. The EPSS score is not provided, so the precise likelihood of exploitation is unknown. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is the delivery of a malicious RTP payload over a network connection that exposes rtpsbcdepay to untrusted traffic, which can trigger the use‑after‑free condition and allow code execution.

Generated by OpenCVE AI on August 20, 2026 at 20:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade GStreamer to a patched release that addresses the use‑after‑free flaw (CWE‑416).
  • Restrict incoming RTP traffic by configuring firewalls or network controls so that only trusted clients can deliver payloads to the application.
  • Enable detailed application and system logging, then monitor for anomalous process activity or unexpected execution patterns that may indicate exploitation attempts.

Generated by OpenCVE AI on August 20, 2026 at 20:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Gstreamer
Gstreamer gstreamer
Vendors & Products Gstreamer
Gstreamer gstreamer

Thu, 20 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Description GStreamer rtpsbcdepay Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the processing of RTP payload elements. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29787.
Title GStreamer rtpsbcdepay Use-After-Free Remote Code Execution Vulnerability
Weaknesses CWE-416
References
Metrics cvssV3_0

{'score': 7.8, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Gstreamer Gstreamer
cve-icon MITRE

Status: PUBLISHED

Assigner: zdi

Published:

Updated: 2026-08-21T03:57:13.463Z

Reserved: 2026-07-29T17:11:07.286Z

Link: CVE-2026-18299

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-20T17:17:26.767

Modified: 2026-08-21T04:17:59.500

Link: CVE-2026-18299

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T20:30:05Z

Weaknesses