Skip to main content

Threats Tagged 'cve-2026-53704'

View all threats tagged with 'cve-2026-53704'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2026-53704

Threats Tagged 'cve-2026-53704'

Click on any threat for detailed analysis and mitigation recommendations

GStreamer is a streaming media framework, based on graphs of elements which operate on media data. This package contains plug-ins whose license is not fully compatible with LGPL. Security Fix(es): * gstreamer1-plugins-ugly-free: GStreamer: Out-of-bounds read in RealMedia demuxer audio stream header parser (CVE-2026-53703) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion

A vulnerability (CVE-2026-53704) was found in GStreamer's RealMedia demuxer within the gst-plugins-ugly package. The flaw involves improper validation of offsets and element counts when parsing specially crafted RealMedia FILEINFO metadata, which can lead to out-of-bounds reads and infinite loops. This may cause applications to crash, hang, or potentially read limited adjacent memory. Red Hat has issued security advisories and released updates for affected Red Hat Enterprise Linux 9 and 10 versions to address this issue.

Join the discussion

A flaw was found in GStreamer's RealMedia demuxer in the gst-plugins-ugly package. When processing a RealMedia file containing a specially crafted FILEINFO metadata section, the demuxer parses variable-name and variable-value pairs using re_skip_pascal_string() without validating that offsets remain within the mapped buffer. Additionally, the element count controlling the parsing loop is read from attacker-controlled data without validation, which can cause an infinite loop. A crafted RealMedia file can cause the application to crash, hang, or potentially read limited adjacent memory contents.

Join the discussion
0

Multiple vulnerabilities have been identified in GStreamer, an open source multimedia framework with a plugin-based architecture supporting various platforms. The advisory from the Bundesamt für Sicherheit in der Informationstechnik references a total of 10 CVEs related to this issue. No specific affected versions or detailed technical descriptions are provided. There is no information about known exploits in the wild or available patches at this time.

Join the discussion

Showing 1 to 4 of 4 results

Filters:Tag: cve-2026-53704
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses