Medium severity6.1NVD Advisory· Published Aug 12, 2026· Updated Sep 23, 2026
CVE-2026-73434
CVE-2026-73434
Description
A flaw was found in GStreamer gst-plugins-good (avidemux). In gst_avi_demux_riff_parse_vprp(), the number of available gst_riff_vprp_video_field_desc entries is calculated by dividing the remaining buffer size by the attacker-controlled vprp->fields value, rather than by sizeof(gst_riff_vprp_video_field_desc). This can cause the parser to treat more field descriptors as available than fit in the input buffer, resulting in out-of-bounds reads. Processing a crafted AVI via playbin/decodebin can crash the application (denial of service). Fixed upstream in gst-plugins-good 1.28.6 (GStreamer-SA-2026-0072).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
8cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*
- osv-coords2 versions
< 1.26.7-2.el10_2.5+ 1 more
- (no CPE)range: < 1.26.7-2.el10_2.5
- (no CPE)range: < 1.26.7-2.el10_2.5
- Range: >=1.28.6
Patches
Vulnerability mechanics
References
15- gstreamer.freedesktop.org/security/sa-2026-0072.htmlnvdPatchVendor Advisory
- access.redhat.com/errata/RHSA-2026:55434nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2026:55436nvdThird Party Advisory
- access.redhat.com/security/cve/CVE-2026-73434nvdThird Party Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party Advisory
- gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12231nvdIssue Tracking
- access.redhat.com/errata/RHSA-2026:56966nvd
- access.redhat.com/errata/RHSA-2026:65959nvd
- access.redhat.com/errata/RHSA-2026:68642nvd
- access.redhat.com/errata/RHSA-2026:68644nvd
- access.redhat.com/errata/RHSA-2026:68645nvd
- access.redhat.com/errata/RHSA-2026:69232nvd
- access.redhat.com/errata/RHSA-2026:70264nvd
- access.redhat.com/errata/RHSA-2026:70584nvd
- access.redhat.com/errata/RHSA-2026:70803nvd
News mentions
0No linked articles in our index yet.