GStreamer MRF OOB Write RCE Vulnerability
CVE-2026-18295 Published on August 20, 2026

GStreamer MRF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
GStreamer MRF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of MRF files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29510.

Vendor Advisory NVD

Weakness Type

What is a Memory Corruption Vulnerability?

The software writes data past the end, or before the beginning, of the intended buffer. Typically, this can result in corruption of data, a crash, or code execution. The software may modify an index or perform pointer arithmetic that references a memory location that is outside of the boundaries of the buffer. A subsequent write operation then produces undefined or unexpected results.

CVE-2026-18295 has been classified to as a Memory Corruption vulnerability or weakness.


Products Associated with CVE-2026-18295

Want to know whenever a new CVE is published for Gstreamer? stack.watch will email you.

 

Affected Versions

GStreamer Version 13fcb641ed33d1472e4ffdec2846180b15405053 is affected by CVE-2026-18295