PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-73433 GStreamer CVE debrief

A flaw in GStreamer's gst-plugins-good (avidemux) can cause heap out-of-bounds read, out-of-bounds write, heap information disclosure, and application crash/denial of service when parsing crafted AVI files. The vulnerability is triggered by opening or previewing a specially crafted AVI file, as the avidemux element is auto-plugged by playbin, decodebin, and gst-discoverer. GStreamer has released a fixed version (1.28.6) to address this issue.

Vendor
GStreamer
Product
gst-plugins-good
CVSS
MEDIUM 6.6
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-12
Original CVE updated
2026-09-23
Advisory published
2026-08-12
Advisory updated
2026-09-23

Who should care

Defenders responsible for GStreamer gst-plugins-good installations, particularly those using the avidemux element, should assess exposure and verify vulnerability. Red Hat Enterprise Linux users should check for applicable security advisories and updates.

Why it matters

CVE-2026-73433 is a medium-severity vulnerability in GStreamer's gst-plugins-good that can cause denial of service, information disclosure, and potential code execution. Defenders should assess exposure, verify vulnerability, and update to version 1.28.6 or later to mitigate risks.

  • Potential denial of service through application crash
  • Possible heap information disclosure of adjacent data
  • Risk of out-of-bounds write leading to code execution or data corruption
  • Exposure of sensitive information through metadata parsing

Technical summary

The avidemux element in GStreamer's gst-plugins-good is vulnerable to a flaw when parsing FUJIFILM metadata in an AVI strd chunk. The gst_avi_demux_parse_strd() function decrements a remaining-length counter by fixed offsets without verifying sufficient data remains, leading to potential heap out-of-bounds read, out-of-bounds write, heap information disclosure, and application crash/denial of service.

Defensive priority

Medium

Recommended defensive actions

  • Assess exposure of GStreamer gst-plugins-good installations to CVE-2026-73433
  • Verify if systems or applications using GStreamer gst-plugins-good are vulnerable
  • Update gst-plugins-good to version 1.28.6 or later
  • Monitor systems for potential denial of service or information disclosure attempts
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The CVE record and NVD detail page provide information on the vulnerability, including its description, CVSS score, and affected products. Red Hat security advisories (RHSA-2026:55434, RHSA-2026:55436, etc.) also provide details on the vulnerability and its impact.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-73433 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-73433

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-73433 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-73433

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.