Medium severity4.3NVD Advisory· Published Jun 23, 2026· Updated Jul 1, 2026
CVE-2026-12891
CVE-2026-12891
Description
A flaw was found in the GStreamer gst-plugins-bad package. When processing a malformed H.266/VVC video stream with a crafted aspect ratio indicator value, the H.266 parser performs an out-of-bounds read of up to 8 bytes from adjacent memory. This flaw allows an attacker to craft a malicious H.266 video file or stream that, when processed by a GStreamer-based application, could leak limited memory contents through video metadata, potentially exposing sensitive information from the application's address space.
Affected products
12- osv-coords7 versionspkg:apk/chainguard/gstreamerpkg:apk/chainguard/gstreamer-docpkg:apk/wolfi/gstreamerpkg:apk/wolfi/gstreamer-devpkg:apk/wolfi/gstreamer-docpkg:apk/chainguard/gstreamer-devpkg:rpm/opensuse/gstreamer-plugins-bad&distro=openSUSE%20Leap%2016.0
< 0+ 6 more
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 1.26.7-160000.3.1
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
2- access.redhat.com/security/cve/CVE-2026-12891nvdThird Party Advisory
- bugzilla.redhat.com/show_bug.cginvdThird Party Advisory
News mentions
0No linked articles in our index yet.