GStreamer before 1.18.4 might access already-freed memory in error code paths when demuxing certain malformed Matroska files.
References
| Link | Resource |
|---|---|
| https://bugzilla.redhat.com/show_bug.cgi?id=1945339 | Issue Tracking Patch Third Party Advisory |
| https://gstreamer.freedesktop.org/security/sa-2021-0002.html | Vendor Advisory |
| https://lists.debian.org/debian-lts-announce/2021/04/msg00027.html | Mailing List Third Party Advisory |
| https://security.gentoo.org/glsa/202208-31 | Third Party Advisory |
| https://www.debian.org/security/2021/dsa-4900 | Third Party Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=1945339 | Issue Tracking Patch Third Party Advisory |
| https://gstreamer.freedesktop.org/security/sa-2021-0002.html | Vendor Advisory |
| https://lists.debian.org/debian-lts-announce/2021/04/msg00027.html | Mailing List Third Party Advisory |
| https://security.gentoo.org/glsa/202208-31 | Third Party Advisory |
| https://www.debian.org/security/2021/dsa-4900 | Third Party Advisory |
Configurations
History
17 Mar 2026, 15:52
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Gstreamer
Gstreamer gstreamer |
|
| CPE | cpe:2.3:a:gstreamer:gstreamer:*:*:*:*:*:*:*:* |
21 Nov 2024, 06:21
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://bugzilla.redhat.com/show_bug.cgi?id=1945339 - Issue Tracking, Patch, Third Party Advisory | |
| References | () https://gstreamer.freedesktop.org/security/sa-2021-0002.html - Vendor Advisory | |
| References | () https://lists.debian.org/debian-lts-announce/2021/04/msg00027.html - Mailing List, Third Party Advisory | |
| References | () https://security.gentoo.org/glsa/202208-31 - Third Party Advisory | |
| References | () https://www.debian.org/security/2021/dsa-4900 - Third Party Advisory |
Information
Published : 2021-04-19 21:15
Updated : 2026-03-17 15:52
NVD link : CVE-2021-3497
Mitre link : CVE-2021-3497
CVE.ORG link : CVE-2021-3497
JSON object : View
Products Affected
redhat
- enterprise_linux
debian
- debian_linux
gstreamer
- gstreamer
CWE
CWE-416
Use After Free
