<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Gst-Plugins-Bad - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/gst-plugins-bad/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 10 Aug 2026 03:50:32 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/gst-plugins-bad/feed.xml" rel="self" type="application/rss+xml"/><item><title>Heap Out-of-Bounds Write in GStreamer adpcmdec Element</title><link>https://feed.craftedsignal.io/briefs/2026-08-gstreamer-heap-overflow/</link><pubDate>Mon, 10 Aug 2026 03:50:32 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-gstreamer-heap-overflow/</guid><description>A heap out-of-bounds write vulnerability in the GStreamer gst-plugins-bad adpcmdec element allows attackers to trigger memory corruption or arbitrary code execution via crafted WAV files.</description><content:encoded><![CDATA[<p>A heap out-of-bounds write vulnerability (CVE-2026-19387) has been identified in the GStreamer gst-plugins-bad adpcmdec element. The vulnerability stems from insufficient validation of per-block sample counts when decoding multi-channel IMA/DVI ADPCM audio streams. By supplying a specially crafted WAV file to an application utilizing this GStreamer plugin, an attacker can induce a write operation that exceeds the bounds of the allocated heap output buffer. Depending on the target application's memory layout and GStreamer integration, this flaw may result in process crashes, denial of service, memory corruption, or potentially arbitrary code execution. This issue affects any software package or media player leveraging GStreamer's bad plugins collection for processing untrusted audio input.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability poses a significant risk to media processing applications across Windows, Linux, and macOS environments that rely on GStreamer plugins. Successful exploitation can lead to a complete compromise of the processing application or a localized denial of service, potentially allowing an attacker to escape sandboxing depending on the privilege level of the media decoding process.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Audit systems to identify applications linked against vulnerable versions of the GStreamer gst-plugins-bad package.</li>
<li>Upgrade to a patched version of GStreamer as provided by your OS distribution or software vendor.</li>
<li>Apply memory integrity and exploit mitigation features (such as ASLR and DEP) at the OS level to hinder reliable exploitation of heap-based corruption.</li>
<li>Restrict access to media processing services if they are exposed to untrusted external input until updates are applied.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>memory-corruption</category></item></channel></rss>