Description
A flaw was found in GStreamer's gst-plugins-good isomp4 plugin. When processing a specially crafted MP4 or MOV file containing CEA-608 closed-caption data, an integer overflow in 32-bit unsigned arithmetic can bypass a bounds check in the caption parser. This leads to an out-of-bounds heap read of up to 244 bytes, which is then included in the downstream caption output. An attacker could exploit this by tricking a user into opening a malicious media file, potentially resulting in disclosure of adjacent heap memory or application crash.
Published: 2026-09-11
Score: 4.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

An integer overflow in GStreamer’s gst-plugins-good isomp4 plugin enables an out‑of‑bounds heap read of up to 244 bytes when parsing CEA‑608 closed‑caption data in specially crafted MP4 or MOV files. The vulnerability allows a crafted media file to leak adjacent heap memory to downstream consumers or trigger an application crash. The weakness corresponds to integer overflow (CWE-190).

Affected Systems

All installations using Red Hat Enterprise Linux 10, 6, 7, 8, and 9 that carry the GStreamer 1.x gst‑plugins‑good package are affected. The vulnerability manifests when media players on those systems process MP4 or MOV files containing CEA‑608 closed‑caption streams.

Risk and Exploitability

The CVSS score of 4.4 indicates a low‑to‑moderate risk, and the EPSS score is currently unavailable, making exploitation probability hard to quantify. The vulnerability is not listed in CISA’s KEV catalog, suggesting it is not widely exploited. The attack vector is user‑initiated opening of a malicious media file, a local or indirect scenario. The impact is limited to potential disclosure of nearby heap memory or an application crash, with no indication of remote code execution.

Generated by OpenCVE AI on September 11, 2026 at 04:43 UTC.

Remediation

Vendor Workaround

No mitigation is currently available that meets Red Hat Product Security's standards for usability, deployment, applicability, or stability.


OpenCVE Recommended Actions

  • Update the GStreamer gst‑plugins‑good package to a version that includes the upstream fix released by Red Hat or the upstream project.
  • Configure media players to disable or ignore CEA‑608 closed‑caption streams in MP4/MOV files, preventing the vulnerable parser from being invoked.
  • Validate that media files originate from trusted sources or sandbox playback to limit memory exposure during decoding.

Generated by OpenCVE AI on September 11, 2026 at 04:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
Title gstreamer1-plugins-good: gstreamer: integer overflow and out-of-bounds read in qtdemux CEA-608 closed-caption parser Gstreamer1-plugins-good: gstreamer: integer overflow and out-of-bounds read in qtdemux cea-608 closed-caption parser
First Time appeared Redhat
Redhat enterprise Linux
CPEs cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
References

Fri, 11 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in GStreamer's gst-plugins-good isomp4 plugin. When processing a specially crafted MP4 or MOV file containing CEA-608 closed-caption data, an integer overflow in 32-bit unsigned arithmetic can bypass a bounds check in the caption parser. This leads to an out-of-bounds heap read of up to 244 bytes, which is then included in the downstream caption output. An attacker could exploit this by tricking a user into opening a malicious media file, potentially resulting in disclosure of adjacent heap memory or application crash.
Title gstreamer1-plugins-good: gstreamer: integer overflow and out-of-bounds read in qtdemux CEA-608 closed-caption parser
Weaknesses CWE-190
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L'}

threat_severity

Moderate


Subscriptions

Redhat Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-11T14:15:50.883Z

Reserved: 2026-09-10T12:58:57.145Z

Link: CVE-2026-88914

cve-icon Vulnrichment

Updated: 2026-09-11T14:15:44.905Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-11T02:18:35.300

Modified: 2026-09-16T19:42:43.623

Link: CVE-2026-88914

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-10T14:00:00Z

Links: CVE-2026-88914 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T19:57:16Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound