CVE-2024-47834 is a critical Use-After-Free (UAF) read vulnerability in GStreamer, a media-handling library, specifically affecting the processing of CodecPrivate elements in Matroska streams. This flaw allows an attacker to cause a denial of service or potentially information disclosure by exploiting freed memory during serialization. With a CVSS score of 9.1 (CRITICAL), it can be exploited remotely without user interaction (AV:N/AC:L/PR:N/UI:N). While no active exploits, public exploit code, or significant community discussion have been observed, the vulnerability is fixed in GStreamer version 1.24.10.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.24.10CPE matchmatch criteria | cpe:2.3:a:gstreamer:gstreamer:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Third-Party Package Updates in Splunk AppDynamics On-Premises Enterprise Console - August 2025
Aug 6, 2025HP ThinPro 8.1 SP6 Security Updates
Mar 3, 2025HP ThinPro 8.1 SP6 Security Updates
Mar 3, 2025HP ThinPro 8.1 SP6 Security Updates
Mar 3, 2025HP ThinPro 8.1 SP6 Security Updates
Mar 3, 2025gstreamer1-plugins-good: Use-After-Free read in Matroska CodecPrivate
Dec 11, 2024