An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's qtdemux_parse_trak function does not sufficiently validate atom data before performing division operations, leading to denial of service due to integer division by zero.
References
| Link | Resource |
|---|---|
| https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/11243.patch | Patch |
| https://gstreamer.freedesktop.org/security/sa-2026-0018.html | Vendor Advisory |
Configurations
History
19 May 2026, 15:15
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Freedesktop gst-plugins-good
Freedesktop |
|
| References | () https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/11243.patch - Patch | |
| References | () https://gstreamer.freedesktop.org/security/sa-2026-0018.html - Vendor Advisory | |
| CPE | cpe:2.3:a:freedesktop:gst-plugins-good:*:*:*:*:*:gstreamer:*:* |
14 May 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-14 18:16
Updated : 2026-05-19 15:15
NVD link : CVE-2026-46469
Mitre link : CVE-2026-46469
CVE.ORG link : CVE-2026-46469
JSON object : View
Products Affected
freedesktop
- gst-plugins-good
CWE
CWE-369
Divide By Zero
