CVE-2026-2922 is a high-severity out-of-bounds write vulnerability in the GStreamer RealMedia Demuxer, affecting GStreamer installations. This flaw, stemming from improper validation of user-supplied data in video packets, allows remote attackers to execute arbitrary code with high impact on confidentiality, integrity, and availability, typically requiring user interaction. With a CVSS score of 7.8, successful exploitation can lead to full compromise of the affected process. While there is no evidence of active exploitation (KEV: No) and no public exploit code available, it has garnered some community discussion and media coverage, indicating awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.28.1CPE matchmatch criteria | cpe:2.3:a:gstreamer:gstreamer:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.