CVE-2026-3085 is a Heap-based Buffer Overflow vulnerability (CWE-122) in GStreamer's rtpqdm2depay component, specifically when processing X-QDM RTP payloads, allowing remote code execution. Rated High with a CVSS score of 8.8, this flaw enables remote attackers to execute arbitrary code with low attack complexity, potentially leading to full compromise of the affected process. Exploitation requires interaction with the GStreamer library, though specific attack vectors may vary. There is currently no evidence of active exploitation in the wild, and public exploit code is not available. However, the vulnerability is being discussed in community forums, indicating some level of awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.28.1CPE matchmatch criteria | cpe:2.3:a:gstreamer:gstreamer:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.