CVE-2026-52722: Integer Overflow or Wraparound in Red Hat Red Hat Enterprise Linux 10
A signed integer overflow vulnerability was found in GStreamer's VMnc decoder. A crafted VMnc stream with large cursor dimensions can overflow signed integer payload-size arithmetic, bypassing a length check and leading to out-of-bounds reads. A remote attacker could trick a user into opening a specially crafted VMnc file, potentially causing a crash or information disclosure.
AI Analysis
Technical Summary
This vulnerability involves a signed integer overflow in the VMnc decoder's cursor payload handling in the gstreamer1-plugins-bad-free package used by Red Hat Enterprise Linux 10. The overflow occurs when processing a crafted VMnc stream with large cursor dimensions, which causes payload-size arithmetic to overflow and bypass length checks, resulting in out-of-bounds reads. This can be triggered remotely by tricking a user into opening a malicious VMnc file. The issue is tracked as CVE-2026-52722 and is part of a security update that addresses multiple vulnerabilities in gstreamer1-plugins-bad-free.
Potential Impact
A remote attacker can cause a denial of service (application crash) or potentially disclose information by exploiting the integer overflow in the VMnc decoder. The vulnerability allows out-of-bounds reads due to bypassed length checks, which may lead to sensitive information exposure or application instability. The CVSS 3.1 base score is 7.1, indicating a high severity impact with network attack vector, low attack complexity, no privileges required, user interaction required, and impact on confidentiality and availability.
Mitigation Recommendations
Red Hat has released an official security update fixing this vulnerability in the gstreamer1-plugins-bad-free package. Users should apply the update to versions 10.2.4 or later of Red Hat Enterprise Linux 10 to remediate this issue. The vendor advisory (RHSA-2026:36749) provides detailed instructions on applying the update. Systems running affected versions (>=10 <10.2.4) are vulnerable until patched. No alternative mitigations are specified beyond applying the official fix.
CVE-2026-52722: Integer Overflow or Wraparound in Red Hat Red Hat Enterprise Linux 10
Description
A signed integer overflow vulnerability was found in GStreamer's VMnc decoder. A crafted VMnc stream with large cursor dimensions can overflow signed integer payload-size arithmetic, bypassing a length check and leading to out-of-bounds reads. A remote attacker could trick a user into opening a specially crafted VMnc file, potentially causing a crash or information disclosure.
CVSS v3.1
Score 7.1high
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability involves a signed integer overflow in the VMnc decoder's cursor payload handling in the gstreamer1-plugins-bad-free package used by Red Hat Enterprise Linux 10. The overflow occurs when processing a crafted VMnc stream with large cursor dimensions, which causes payload-size arithmetic to overflow and bypass length checks, resulting in out-of-bounds reads. This can be triggered remotely by tricking a user into opening a malicious VMnc file. The issue is tracked as CVE-2026-52722 and is part of a security update that addresses multiple vulnerabilities in gstreamer1-plugins-bad-free.
Potential Impact
A remote attacker can cause a denial of service (application crash) or potentially disclose information by exploiting the integer overflow in the VMnc decoder. The vulnerability allows out-of-bounds reads due to bypassed length checks, which may lead to sensitive information exposure or application instability. The CVSS 3.1 base score is 7.1, indicating a high severity impact with network attack vector, low attack complexity, no privileges required, user interaction required, and impact on confidentiality and availability.
Mitigation Recommendations
Red Hat has released an official security update fixing this vulnerability in the gstreamer1-plugins-bad-free package. Users should apply the update to versions 10.2.4 or later of Red Hat Enterprise Linux 10 to remediate this issue. The vendor advisory (RHSA-2026:36749) provides detailed instructions on applying the update. Systems running affected versions (>=10 <10.2.4) are vulnerable until patched. No alternative mitigations are specified beyond applying the official fix.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2026-06-08T11:07:26.009Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-52722","vendor":"Red Hat"}]
Threat ID: 6a3052fb0b89be6888827ce5
Added to database: 06/15/2026, 19:31:07 UTC
Last enriched: 07/29/2026, 21:33:25 UTC
Last updated: 07/31/2026, 21:26:43 UTC
Views: 64
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.