CVE-2026-1940

An incomplete fix for CVE-2024-47778 allows an out-of-bounds read in gst_wavparse_adtl_chunk() function. The patch added a size validation check lsize + 8 > size, but it does not account for the GST_ROUND_UP_2(lsize) used in the actual offset calculation. When lsize is an odd number, the parser advances more bytes than validated, causing OOB read.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:freedesktop:gst-plugins-good:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:gstreamer:gstreamer:*:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:12.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-03-23 22:16

Updated : 2026-06-17 10:16


NVD link : CVE-2026-1940

Mitre link : CVE-2026-1940

CVE.ORG link : CVE-2026-1940


JSON object : View

Products Affected

freedesktop

  • gst-plugins-good

gstreamer

  • gstreamer

debian

  • debian_linux

redhat

  • enterprise_linux
CWE
CWE-125

Out-of-bounds Read