Description
A NULL pointer dereference flaw was found in GStreamer's RTSP support library. The vulnerability occurs while parsing an Authorization or WWW-Authenticate header that uses Digest authentication. Specially crafted whitespace placement around a parameter's terminator can cause an internal length calculation to underflow, leading to a crash of the process parsing the header. On an RTSP server this can be triggered by a remote, unauthenticated attacker sending a single malformed request when the server has authentication enabled; the same flaw can also be triggered against an RTSP client by a malicious or compromised RTSP server. Successful exploitation results in a denial of service (application crash) and has no confirmed impact on confidentiality or integrity.
Published: 2026-09-03
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A NULL pointer dereference flaw exists in GStreamer’s RTSP support library, triggered when parsing an Authorization or WWW‑Authenticate header that uses Digest authentication. Specially crafted whitespace around a parameter terminator can cause an internal length calculation to underflow, leading to a process crash. The result is a denial of service; there is no confirmed impact on confidentiality or integrity.

Affected Systems

The flaw affects Red Hat Enterprise Linux 7, 8, 9, and 10 systems that run the GStreamer RTSP library. No specific product version ranges are supplied, but any installation of GStreamer on these operating systems is potentially vulnerable.

Risk and Exploitability

The CVSS score of 7.5 indicates high severity. EPSS data are not available, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is a remote, unauthenticated attacker who can send a single malformed RTSP request to a server or client that has RTSP enabled. Successful exploitation results in an application crash, causing service downtime, but does not grant the attacker access to data or system control.

Generated by OpenCVE AI on September 3, 2026 at 12:49 UTC.

Remediation

Vendor Workaround

No mitigation is currently available that meets Red Hat Product Security's standards for usability, deployment, applicability, or stability.


OpenCVE Recommended Actions

  • Install any available Red Hat update or GStreamer package that includes the patch for CVE‑2026‑85150.
  • Disable or remove the GStreamer‑based RTSP server if it is not required, or replace it with a hardened alternative.
  • Restrict network access to the RTSP service by applying firewall rules or network segmentation to limit exposure to untrusted hosts.
  • Enable logging and monitor RTSP traffic for anomalous Authorization or WWW‑Authenticate headers; investigate any malformed requests.

Generated by OpenCVE AI on September 3, 2026 at 12:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Freedesktop
Freedesktop gstreamer
Vendors & Products Freedesktop
Freedesktop gstreamer

Thu, 03 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 03 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Thu, 03 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Description A NULL pointer dereference flaw was found in GStreamer's RTSP support library. The vulnerability occurs while parsing an Authorization or WWW-Authenticate header that uses Digest authentication. Specially crafted whitespace placement around a parameter's terminator can cause an internal length calculation to underflow, leading to a crash of the process parsing the header. On an RTSP server this can be triggered by a remote, unauthenticated attacker sending a single malformed request when the server has authentication enabled; the same flaw can also be triggered against an RTSP client by a malicious or compromised RTSP server. Successful exploitation results in a denial of service (application crash) and has no confirmed impact on confidentiality or integrity.
Title Gstreamer1-plugins-base: gstreamer: null/invalid-pointer dereference in gst_rtsp_message_parse_auth_credentials() when parsing a crafted digest authorization/www-authenticate header
First Time appeared Redhat
Redhat enterprise Linux
Weaknesses CWE-476
CPEs cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Freedesktop Gstreamer
Redhat Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-03T12:34:05.679Z

Reserved: 2026-09-03T10:21:17.760Z

Link: CVE-2026-85150

cve-icon Vulnrichment

Updated: 2026-09-03T12:34:00.557Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-03T13:06:21.910

Modified: 2026-09-03T18:12:56.407

Link: CVE-2026-85150

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-03T10:25:00Z

Links: CVE-2026-85150 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T15:33:19Z

Weaknesses