CVE-2026-73433
Description
A flaw was found in GStreamer gst-plugins-good (avidemux). When parsing FUJIFILM metadata in an AVI strd chunk, gst_avi_demux_parse_strd() decrements a remaining-length counter by fixed offsets (98 and 10 bytes) without verifying sufficient data remains. For crafted strd payloads of exactly 106 or 107 bytes, the counter underflows to a very large unsigned value, causing subsequent null-terminated string scanning to read far beyond the allocated heap buffer. Date-format normalization may also write beyond the buffer end. Confirmed impacts include heap out-of-bounds read, out-of-bounds write, heap information disclosure (adjacent data appearing in parsed metadata), and application crash/denial of service. The avidemux element is auto-plugged by playbin, decodebin, and gst-discoverer, so opening or previewing a crafted AVI is sufficient to trigger the issue. Fixed upstream in gst-plugins-good 1.28.6 (GStreamer-SA-2026-0072).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
8cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
- Range: >=1.28.6
- osv-coords2 versions
< 1.26.7-2.el10_2.5+ 1 more
- (no CPE)range: < 1.26.7-2.el10_2.5
- (no CPE)range: < 1.26.7-2.el10_2.5
Patches
Vulnerability mechanics
References
15- gstreamer.freedesktop.org/security/sa-2026-0072.htmlnvdPatchVendor Advisory
- access.redhat.com/errata/RHSA-2026:55434nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2026:55436nvdThird Party Advisory
- access.redhat.com/security/cve/CVE-2026-73433nvdThird Party Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party Advisory
- gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12231nvdIssue Tracking
- access.redhat.com/errata/RHSA-2026:56966nvd
- access.redhat.com/errata/RHSA-2026:65959nvd
- access.redhat.com/errata/RHSA-2026:68642nvd
- access.redhat.com/errata/RHSA-2026:68644nvd
- access.redhat.com/errata/RHSA-2026:68645nvd
- access.redhat.com/errata/RHSA-2026:69232nvd
- access.redhat.com/errata/RHSA-2026:70264nvd
- access.redhat.com/errata/RHSA-2026:70584nvd
- access.redhat.com/errata/RHSA-2026:70803nvd
News mentions
0No linked articles in our index yet.