CVE-2026-2920 is a high-severity heap-based buffer overflow vulnerability in the GStreamer ASF Demuxer, enabling remote attackers to achieve arbitrary code execution on affected GStreamer installations. This flaw, stemming from improper validation of user-supplied data in ASF file stream headers, has a CVSS score of 7.8 and requires user interaction, such as opening a malicious file, for exploitation. Successful attacks can lead to complete compromise of confidentiality, integrity, and availability by executing code in the context of the current process with low attack complexity. While not listed in CISA's KEV catalog, this vulnerability is on a "Hot List: Active" indicating heightened monitoring, and has received some community discussion and media coverage, though no public exploit code is currently available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.28.1CPE matchmatch criteria | cpe:2.3:a:gstreamer:gstreamer:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.