{"id":"CVE-2026-73434","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-73434","summary":"A flaw was found in GStreamer gst-plugins-good (avidemux). In gst_avi_demux_riff_parse_vprp(), the number of available gst_riff_vprp_video_field_desc entries is calculated by dividing…","details":"A flaw was found in GStreamer gst-plugins-good (avidemux). In gst_avi_demux_riff_parse_vprp(), the number of available gst_riff_vprp_video_field_desc entries is calculated by dividing the remaining buffer size by the attacker-controlled vprp->fields value, rather than by sizeof(gst_riff_vprp_video_field_desc). This can cause the parser to treat more field descriptors as available than fit in the input buffer, resulting in out-of-bounds reads. Processing a crafted AVI via playbin/decodebin can crash the application (denial of service). Fixed upstream in gst-plugins-good 1.28.6 (GStreamer-SA-2026-0072).","published":"2026-08-12T19:05:23.429Z","modified":"2026-08-12T19:05:23.429Z","cvss":{"score":7.1,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-73434"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2514807"},{"type":"WEB","url":"https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12231"},{"type":"WEB","url":"https://gstreamer.freedesktop.org/security/sa-2026-0072.html"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T19:05:23.429Z"}}