A flaw was found in GStreamer's gst-plugins-good isomp4 plugin. When processing a specially crafted MP4 or MOV file containing CEA-608 closed-caption data, an integer overflow in 32-bit unsigned arithmetic can bypass a bounds check in the caption parser. This leads to an out-of-bounds heap read of up to 244 bytes, which is then included in the downstream caption output. An attacker could exploit this by tricking a user into opening a malicious media file, potentially resulting in disclosure of adjacent heap memory or application crash.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No mitigation is currently available that meets Red Hat Product Security's standards for usability, deployment, applicability, or stability.

History

Fri, 11 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
Title gstreamer1-plugins-good: gstreamer: integer overflow and out-of-bounds read in qtdemux CEA-608 closed-caption parser Gstreamer1-plugins-good: gstreamer: integer overflow and out-of-bounds read in qtdemux cea-608 closed-caption parser
First Time appeared Redhat
Redhat enterprise Linux
CPEs cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
References

Fri, 11 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in GStreamer's gst-plugins-good isomp4 plugin. When processing a specially crafted MP4 or MOV file containing CEA-608 closed-caption data, an integer overflow in 32-bit unsigned arithmetic can bypass a bounds check in the caption parser. This leads to an out-of-bounds heap read of up to 244 bytes, which is then included in the downstream caption output. An attacker could exploit this by tricking a user into opening a malicious media file, potentially resulting in disclosure of adjacent heap memory or application crash.
Title gstreamer1-plugins-good: gstreamer: integer overflow and out-of-bounds read in qtdemux CEA-608 closed-caption parser
Weaknesses CWE-190
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L'}

threat_severity

Moderate


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-11T01:48:43.886Z

Reserved: 2026-09-10T12:58:57.145Z

Link: CVE-2026-88914

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T02:18:35.300

Modified: 2026-09-11T02:18:35.300

Link: CVE-2026-88914

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-10T14:00:00Z

Links: CVE-2026-88914 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T04:45:18Z

Weaknesses