Description
A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio. Insufficient validation of the per-block sample count for multi-channel streams allows a crafted WAV file to cause writes beyond the allocated output buffer. This can lead to application crash, denial of service, memory corruption, or potentially arbitrary code execution when untrusted media is processed.
Published: 2026-08-10
Score: 7.6 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A heap out‑of‑bounds write was discovered in the GStreamer gst‑plugins‑bad adpcmdec element when decoding IMA/DVI ADPCM audio. The plugin fails to validate the per‑block sample count for multi‑channel streams, so an attacker can craft a WAV file that writes beyond the allocated output buffer. The resulting memory corruption can crash the application, cause denial of service, or lead to arbitrary code execution within the context of the process that processes the file.

Affected Systems

The flaw affects Red Hat Enterprise Linux 7, 8, 9 and 10, where the gstreamer1‑plugins‑bad‑free package is installed. Any application that uses GStreamer to play or decode IMA ADPCM WAV files, such as media players, transcoding tools, or streaming servers, is at risk if it runs on these distributions.

Risk and Exploitability

The CVSS score of 7.6 indicates a high severity vulnerability. EPSS is not available and the flaw is not yet listed in the CISA KEV catalog, but its impact for untrusted media handling can be severe. The likely attack vector is local or indirect via applications that ingest user‑supplied media; a malicious WAV file would need to be processed by an affected application. Without a vendor patch, the only available mitigation is to avoid loading untrusted multi‑channel IMA ADPCM WAV files and to sandbox or otherwise isolate media‑handling applications.

Generated by OpenCVE AI on August 10, 2026 at 04:21 UTC.

Remediation

Vendor Workaround

To mitigate this issue, users should avoid playing or processing untrusted multi-channel IMA ADPCM WAV files. Additionally, consider sandboxing applications that handle untrusted media to limit the potential impact of exploitation.


OpenCVE Recommended Actions

  • Apply the latest Red Hat security update that contains the fixed version of the gstreamer1‑plugins‑bad package.
  • If no update is available, do not play or process untrusted multi‑channel IMA ADPCM WAV files.
  • Run media‑processing applications in a sandbox or restricted container to limit the impact of any potential exploitation.
  • Optionally, disable the adpcmdec plugin in GStreamer if the functionality is not required.

Generated by OpenCVE AI on August 10, 2026 at 04:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 10 Aug 2026 03:15:00 +0000

Type Values Removed Values Added
Description A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio. Insufficient validation of the per-block sample count for multi-channel streams allows a crafted WAV file to cause writes beyond the allocated output buffer. This can lead to application crash, denial of service, memory corruption, or potentially arbitrary code execution when untrusted media is processed.
Title Gstreamer: gstreamer1-plugins-bad-free: gstreamer: heap out-of-bounds write in adpcmdec ima/dvi adpcm decoder
First Time appeared Redhat
Redhat enterprise Linux
Weaknesses CWE-787
CPEs cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H'}


Subscriptions

Redhat Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-08-10T02:36:52.235Z

Reserved: 2026-08-10T02:22:33.834Z

Link: CVE-2026-19387

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-10T04:30:11Z

Weaknesses