High severity7.8NVD Advisory· Published Apr 19, 2021· Updated Jun 17, 2026
CVE-2021-3498
CVE-2021-3498
Description
GStreamer before 1.18.4 might cause heap corruption when parsing certain malformed Matroska files.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6- GStreamer/GStreamerdescription
- osv-coords4 versionspkg:rpm/opensuse/gstreamer-plugins-good&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/gstreamer-plugins-good&distro=openSUSE%20Leap%2015.3pkg:rpm/suse/gstreamer-plugins-good&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP2pkg:rpm/suse/gstreamer-plugins-good&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP3
< 1.16.3-lp152.2.6.1+ 3 more
- (no CPE)range: < 1.16.3-lp152.2.6.1
- (no CPE)range: < 1.16.3-3.6.1
- (no CPE)range: < 1.16.3-3.6.1
- (no CPE)range: < 1.16.3-3.6.1
Patches
Vulnerability mechanics
References
5- bugzilla.redhat.com/show_bug.cginvdIssue TrackingPatchThird Party Advisory
- packetstormsecurity.com/files/162952/Gstreamer-Matroska-Demuxing-Use-After-Free.htmlnvdThird Party AdvisoryVDB Entry
- gstreamer.freedesktop.org/security/sa-2021-0003.htmlnvdVendor Advisory
- security.gentoo.org/glsa/202208-31nvdThird Party Advisory
- www.debian.org/security/2021/dsa-4900nvdMailing ListThird Party Advisory
News mentions
0No linked articles in our index yet.