CVE-2026-19389

Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdemux) when parsing header objects from crafted ASF, WMV, or WMA files. Insufficient validation of attacker-controlled length and size values can bypass bounds checks and cause out-of-bounds heap reads. This can result in application crash, denial of service, or limited information disclosure when untrusted media is processed.
Configurations

No configuration.

History

16 Sep 2026, 13:17

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:67882 -
  • () https://access.redhat.com/errata/RHSA-2026:67930 -
  • () https://access.redhat.com/errata/RHSA-2026:67931 -

Information

Published : 2026-08-10 03:16

Updated : 2026-09-16 13:17


NVD link : CVE-2026-19389

Mitre link : CVE-2026-19389

CVE.ORG link : CVE-2026-19389


JSON object : View

Products Affected

No product.

CWE
CWE-190

Integer Overflow or Wraparound