Description
Multiple out-of-bounds read vulnerabilities were found in GStreamer's pcapparse element. Malformed PCAP records can trigger reads beyond buffer boundaries during IPv4/TCP header parsing. This element is primarily used in debugging pipelines, limiting real-world exposure. A local attacker could trick a user into processing a specially crafted PCAP file, potentially leading to a crash or information disclosure.
Problem types
Product status
Timeline
| 2026-05-19: | Reported to Red Hat. |
| 2026-06-15: | Made public. |
Credits
Red Hat would like to thank JUNYI LIU for reporting this issue.
References
access.redhat.com/security/cve/CVE-2026-52721
bugzilla.redhat.com/show_bug.cgi?id=2486732 (RHBZ#2486732)
gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5106