Upstream information

CVE-2026-18649 at MITRE

Description

A flaw was found in the GStreamer gst-plugins-good package. The rtph264depay and rtph265depay RTP depayloader elements do not enforce a maximum size limit on the reassembly buffer used during fragmented RTP packet processing. A remote, unauthenticated attacker can send a continuous stream of RTP fragments without ever transmitting an end-of-fragment marker, causing the reassembly buffer to grow without bound until process memory is exhausted. This results in a denial of service through process termination.

SUSE information

Overall state of this security issue: Resolved

This issue is currently rated as having important severity.

CVSS v3 Scores
CVSS detail CNA (Red Hat)
Base Score 7.5
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality Impact None
Integrity Impact None
Availability Impact High
CVSSv3 Version 3.1
No SUSE Bugzilla entries cross referenced.

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
SUSE Liberty Linux 10
  • gstreamer1-plugins-good >= 1.26.7-2.el10_2.3
  • gstreamer1-plugins-good-gtk >= 1.26.7-2.el10_2.3
Patchnames:
RHSA-2026:53451
SUSE Liberty Linux 8
  • gstreamer1-plugins-good >= 1.16.1-7.el8_10.3
  • gstreamer1-plugins-good-gtk >= 1.16.1-7.el8_10.3
Patchnames:
RHSA-2026:56966
SUSE Liberty Linux 9
  • gstreamer1-plugins-good >= 1.22.12-7.el9_8.2
  • gstreamer1-plugins-good-gtk >= 1.22.12-7.el9_8.2
Patchnames:
RHSA-2026:53452


SUSE Timeline for this CVE

CVE page created: Wed Aug 12 20:49:16 2026
CVE page last modified: Thu Aug 20 21:03:43 2026