Out-of-bounds Write Affecting gstreamer1-plugins-bad-free-debugsource package, versions <0:1.24.10-1.amzn2023.0.6


Severity

Recommended
high

Based on Amazon Linux security rating.

Threat Intelligence

EPSS
0.23% (14th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-AMZN2023-GSTREAMER1PLUGINSBADFREEDEBUGSOURCE-17887872
  • published8 Jul 2026
  • disclosed11 Jun 2026

Introduced: 11 Jun 2026

CVE-2026-53702  (opens in a new tab)
CWE-787  (opens in a new tab)

How to fix?

Upgrade Amazon-Linux:2023 gstreamer1-plugins-bad-free-debugsource to version 0:1.24.10-1.amzn2023.0.6 or higher.
This issue was patched in ALAS2023-2026-1917.

NVD Description

Note: Versions mentioned in the description apply only to the upstream gstreamer1-plugins-bad-free-debugsource package and not the gstreamer1-plugins-bad-free-debugsource package as distributed by Amazon-Linux. See How to fix? for Amazon-Linux:2023 relevant fixed versions and status.

A stack buffer overflow flaw was found in the GStreamer H.265 codec parser library (gst-plugins-bad). When parsing a buffering period SEI message, the parser uses an incorrect loop bound derived from cpb_cnt_minus1[i] (the loop index) instead of the sub-layer 0 CPB count cpb_cnt_minus1[0] from the referenced Sequence Parameter Set. A crafted H.265 video file or stream can cause the parser to write beyond the bounds of stack-allocated CPB delay arrays, resulting in a crash or potential stack memory corruption.

CVSS Base Scores

version 3.1