Unrated severityNVD Advisory· Published Dec 11, 2024· Updated Nov 3, 2025
GHSL-2024-195: GStreamer has an OOB-write in convert_to_s334_1a
CVE-2024-47539
Description
GStreamer is a library for constructing graphs of media-handling components. An out-of-bounds write vulnerability was identified in the convert_to_s334_1a function in isomp4/qtdemux.c. The vulnerability arises due to a discrepancy between the size of memory allocated to the storage array and the loop condition i * 2 < ccpair_size. Specifically, when ccpair_size is even, the allocated size in storage does not match the loop's expected bounds, resulting in an out-of-bounds write. This bug allows for the overwriting of up to 3 bytes beyond the allocated bounds of the storage array. This vulnerability is fixed in 1.24.10.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
22- osv-coords20 versionspkg:rpm/almalinux/gstreamer1-plugins-goodpkg:rpm/almalinux/gstreamer1-plugins-good-gtkpkg:rpm/opensuse/gstreamer-plugins-good&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/gstreamer-plugins-good&distro=openSUSE%20Tumbleweedpkg:rpm/suse/gstreamer-plugins-good&distro=SUSE%20Enterprise%20Storage%207.1pkg:rpm/suse/gstreamer-plugins-good&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP3-LTSSpkg:rpm/suse/gstreamer-plugins-good&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOSpkg:rpm/suse/gstreamer-plugins-good&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSSpkg:rpm/suse/gstreamer-plugins-good&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-ESPOSpkg:rpm/suse/gstreamer-plugins-good&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-LTSSpkg:rpm/suse/gstreamer-plugins-good&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP6pkg:rpm/suse/gstreamer-plugins-good&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP3-LTSSpkg:rpm/suse/gstreamer-plugins-good&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSSpkg:rpm/suse/gstreamer-plugins-good&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP5-LTSSpkg:rpm/suse/gstreamer-plugins-good&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP3pkg:rpm/suse/gstreamer-plugins-good&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4pkg:rpm/suse/gstreamer-plugins-good&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP5pkg:rpm/suse/gstreamer-plugins-good&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP6pkg:rpm/suse/gstreamer-plugins-good&distro=SUSE%20Manager%20Proxy%204.3pkg:rpm/suse/gstreamer-plugins-good&distro=SUSE%20Manager%20Server%204.3
< 1.22.1-3.el9_5+ 19 more
- (no CPE)range: < 1.22.1-3.el9_5
- (no CPE)range: < 1.22.1-3.el9_5
- (no CPE)range: < 1.24.0-150600.3.3.1
- (no CPE)range: < 1.24.10-3.1
- (no CPE)range: < 1.16.3-150200.3.17.1
- (no CPE)range: < 1.16.3-150200.3.17.1
- (no CPE)range: < 1.20.1-150400.3.9.1
- (no CPE)range: < 1.20.1-150400.3.9.1
- (no CPE)range: < 1.22.0-150500.4.6.1
- (no CPE)range: < 1.22.0-150500.4.6.1
- (no CPE)range: < 1.24.0-150600.3.3.1
- (no CPE)range: < 1.16.3-150200.3.17.1
- (no CPE)range: < 1.20.1-150400.3.9.1
- (no CPE)range: < 1.22.0-150500.4.6.1
- (no CPE)range: < 1.16.3-150200.3.17.1
- (no CPE)range: < 1.20.1-150400.3.9.1
- (no CPE)range: < 1.22.0-150500.4.6.1
- (no CPE)range: < 1.24.0-150600.3.3.1
- (no CPE)range: < 1.20.1-150400.3.9.1
- (no CPE)range: < 1.20.1-150400.3.9.1
Patches
Vulnerability mechanics
References
3- gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/8059.patchmitrex_refsource_MISC
- gstreamer.freedesktop.org/security/sa-2024-0007.htmlmitrex_refsource_MISC
- securitylab.github.com/advisories/GHSL-2024-195_Gstreamer/mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.