CVE-2026-46469

MEDIUM

GStreamer Good Plug-ins < 1.28.2 - Denial of Service via MP4 Audio Track Atom Parsing

Title source: llm
STIX 2.1

Description

An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's qtdemux_parse_trak function does not sufficiently validate atom data before performing division operations, leading to denial of service due to integer division by zero.

Scores

CVSS v3 4.0
EPSS 0.0010
EPSS Percentile 1.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-369
Status published
Products (2)
freedesktop/gst-plugins-good < 1.28.2
GStreamer/Good Plug-ins < 1.28.2
Published May 14, 2026
Tracked Since May 15, 2026