PatchSiren cyber security CVE debrief
CVE-2026-73433 GStreamer CVE debrief
A flaw in GStreamer's gst-plugins-good (avidemux) can cause heap out-of-bounds read, out-of-bounds write, heap information disclosure, and application crash/denial of service when parsing crafted AVI files. The vulnerability is triggered by opening or previewing a specially crafted AVI file, as the avidemux element is auto-plugged by playbin, decodebin, and gst-discoverer. GStreamer has released a fixed version (1.28.6) to address this issue.
- Vendor
- GStreamer
- Product
- gst-plugins-good
- CVSS
- MEDIUM 6.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-12
- Original CVE updated
- 2026-09-23
- Advisory published
- 2026-08-12
- Advisory updated
- 2026-09-23
Who should care
Defenders responsible for GStreamer gst-plugins-good installations, particularly those using the avidemux element, should assess exposure and verify vulnerability. Red Hat Enterprise Linux users should check for applicable security advisories and updates.
Why it matters
CVE-2026-73433 is a medium-severity vulnerability in GStreamer's gst-plugins-good that can cause denial of service, information disclosure, and potential code execution. Defenders should assess exposure, verify vulnerability, and update to version 1.28.6 or later to mitigate risks.
- Potential denial of service through application crash
- Possible heap information disclosure of adjacent data
- Risk of out-of-bounds write leading to code execution or data corruption
- Exposure of sensitive information through metadata parsing
Technical summary
The avidemux element in GStreamer's gst-plugins-good is vulnerable to a flaw when parsing FUJIFILM metadata in an AVI strd chunk. The gst_avi_demux_parse_strd() function decrements a remaining-length counter by fixed offsets without verifying sufficient data remains, leading to potential heap out-of-bounds read, out-of-bounds write, heap information disclosure, and application crash/denial of service.
Defensive priority
Medium
Recommended defensive actions
- Assess exposure of GStreamer gst-plugins-good installations to CVE-2026-73433
- Verify if systems or applications using GStreamer gst-plugins-good are vulnerable
- Update gst-plugins-good to version 1.28.6 or later
- Monitor systems for potential denial of service or information disclosure attempts
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE record and NVD detail page provide information on the vulnerability, including its description, CVSS score, and affected products. Red Hat security advisories (RHSA-2026:55434, RHSA-2026:55436, etc.) also provide details on the vulnerability and its impact.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-73433 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-73433
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-73433 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-73433
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:55434
[email protected] - Third Party Advisory
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:55436
[email protected] - Third Party Advisory
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:56966
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:65959
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:68642
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:68644
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:68645
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/security/cve/CVE-2026-73433
[email protected] - Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.