Impact
A heap out‑of‑bounds write was discovered in the GStreamer gst‑plugins‑bad adpcmdec element when decoding IMA/DVI ADPCM audio. The plugin fails to validate the per‑block sample count for multi‑channel streams, so an attacker can craft a WAV file that writes beyond the allocated output buffer. The resulting memory corruption can crash the application, cause denial of service, or lead to arbitrary code execution within the context of the process that processes the file.
Affected Systems
The flaw affects Red Hat Enterprise Linux 7, 8, 9 and 10, where the gstreamer1‑plugins‑bad‑free package is installed. Any application that uses GStreamer to play or decode IMA ADPCM WAV files, such as media players, transcoding tools, or streaming servers, is at risk if it runs on these distributions.
Risk and Exploitability
The CVSS score of 7.6 indicates a high severity vulnerability. EPSS is not available and the flaw is not yet listed in the CISA KEV catalog, but its impact for untrusted media handling can be severe. The likely attack vector is local or indirect via applications that ingest user‑supplied media; a malicious WAV file would need to be processed by an affected application. Without a vendor patch, the only available mitigation is to avoid loading untrusted multi‑channel IMA ADPCM WAV files and to sandbox or otherwise isolate media‑handling applications.
OpenCVE Enrichment