Impact
An integer overflow in GStreamer’s gst-plugins-good isomp4 plugin enables an out‑of‑bounds heap read of up to 244 bytes when parsing CEA‑608 closed‑caption data in specially crafted MP4 or MOV files. The vulnerability allows a crafted media file to leak adjacent heap memory to downstream consumers or trigger an application crash. The weakness corresponds to integer overflow (CWE-190).
Affected Systems
All installations using Red Hat Enterprise Linux 10, 6, 7, 8, and 9 that carry the GStreamer 1.x gst‑plugins‑good package are affected. The vulnerability manifests when media players on those systems process MP4 or MOV files containing CEA‑608 closed‑caption streams.
Risk and Exploitability
The CVSS score of 4.4 indicates a low‑to‑moderate risk, and the EPSS score is currently unavailable, making exploitation probability hard to quantify. The vulnerability is not listed in CISA’s KEV catalog, suggesting it is not widely exploited. The attack vector is user‑initiated opening of a malicious media file, a local or indirect scenario. The impact is limited to potential disclosure of nearby heap memory or an application crash, with no indication of remote code execution.
OpenCVE Enrichment