PatchSiren cyber security CVE debrief
CVE-2026-18649 Red Hat CVE debrief
A flaw was found in the GStreamer gst-plugins-good package. The rtph264depay and rtph265depay RTP depayloader elements do not enforce a maximum size limit on the reassembly buffer used during fragmented RTP packet processing. A remote, unauthenticated attacker can send a continuous stream of RTP fragments without ever transmitting an end-of-fragment marker, causing the reassembly buffer to grow without bound until process memory is exhausted. This results in a denial of service through process termination.
- Vendor
- Red Hat
- Product
- Red Hat Enterprise Linux 10
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-06
- Original CVE updated
- 2026-08-06
- Advisory published
- 2026-08-06
- Advisory updated
- 2026-08-06
Who should care
Organizations using the GStreamer gst-plugins-good package should be aware of this vulnerability and take steps to mitigate the risk. This includes reviewing and applying vendor-provided patches or updates, implementing network segmentation and isolation, and monitoring network traffic for suspicious activity.
Technical summary
The rtph264depay and rtph265depay RTP depayloader elements in the GStreamer gst-plugins-good package do not enforce a maximum size limit on the reassembly buffer used during fragmented RTP packet processing. This allows a remote, unauthenticated attacker to send a continuous stream of RTP fragments without ever transmitting an end-of-fragment marker, causing the reassembly buffer to grow without bound until process memory is exhausted, resulting in a denial of service through process termination.
Defensive priority
High-priority defensive actions are required to address this vulnerability, as it can be exploited remotely without authentication, leading to a denial of service.
Recommended defensive actions
- Review and apply vendor-provided patches or updates to address the vulnerability.
- Implement network segmentation and isolation to limit the attack surface.
- Monitor network traffic for suspicious RTP packet activity.
- Consider implementing compensating controls, such as rate limiting or traffic shaping, to mitigate the impact of a potential exploit.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
Evidence notes
The CVE record and NVD entry provide details about the vulnerability in the GStreamer gst-plugins-good package. However, the information available is limited, and further analysis is required to fully understand the impact and affected scope.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T08:16:29.780Z and has not been modified since then.