PatchSiren cyber security CVE debrief
CVE-2026-46470 GStreamer CVE debrief
An integer division-by-zero vulnerability exists in GStreamer gst-plugins-good before version 1.28.2. The flaw resides in the isomp4 plugin's qtdemux_audio_caps function, which fails to adequately validate atom data from MP4 audio tracks before performing division operations. This validation gap can trigger a denial-of-service condition when processing malformed MP4 files. The vulnerability was published on 2026-05-14 and last modified on 2026-05-19. It carries a CVSS 3.1 score of 4.0 (MEDIUM severity) with an attack vector of local, low attack complexity, and low availability impact. The weakness is categorized as CWE-369 (Divide By Zero). No known exploitation in ransomware campaigns has been reported, and the vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog.
- Vendor
- GStreamer
- Product
- Good Plug-ins
- CVSS
- MEDIUM 4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-14
- Original CVE updated
- 2026-05-19
- Advisory published
- 2026-05-14
- Advisory updated
- 2026-05-19
Who should care
Organizations and developers utilizing GStreamer for multimedia processing, particularly those handling MP4 audio content from untrusted sources. System administrators maintaining media servers, transcoding pipelines, or desktop environments with GStreamer dependencies should prioritize patching. Security teams monitoring for denial-of-service vectors in multimedia parsing libraries should track this vulnerability.
Technical summary
The isomp4 plugin in GStreamer gst-plugins-good versions prior to 1.28.2 contains a validation flaw in the qtdemux_audio_caps function. When parsing atom data from MP4 audio tracks, the function performs division operations without sufficient validation of input values, resulting in potential integer division by zero. This condition causes denial of service through application crash or hang when processing crafted MP4 files. The vulnerability is exploitable locally with low attack complexity and requires no privileges or user interaction.
Defensive priority
medium
Recommended defensive actions
- Upgrade GStreamer gst-plugins-good to version 1.28.2 or later to remediate the division-by-zero vulnerability in MP4 audio track parsing.
- Apply the vendor-provided patch from the GStreamer merge request if immediate upgrading is not feasible.
- Review and restrict processing of untrusted MP4 audio files in environments where GStreamer is deployed.
- Monitor GStreamer security advisories for additional guidance related to SA-2026-0018.
Evidence notes
The vulnerability description and affected version range (prior to 1.28.2) are derived from NVD CPE criteria and the official CVE record. The specific function (qtdemux_audio_caps) and plugin (isomp4) are identified in the CVE description. CVSS vector and CWE classification are sourced from NVD metadata.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-46470 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-46470
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-46470 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-46470
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/11243.patch
[email protected] - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://gstreamer.freedesktop.org/security/sa-2026-0018.html
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.