QSearchQSearch

CVE-2026-52721

5.3 MEDIUM

Multiple out-of-bounds read vulnerabilities were found in GStreamer's pcapparse element

Published: 2026-06-15 · Last updated: 2026-06-15

Severity and scoring

CVSS
5.3 MEDIUM
Vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:H
CWE
CWE-125

Description

Multiple out-of-bounds read vulnerabilities were found in GStreamer's pcapparse element. Malformed PCAP records can trigger reads beyond buffer boundaries during IPv4/TCP header parsing. This element is primarily used in debugging pipelines, limiting real-world exposure. A local attacker could trick a user into processing a specially crafted PCAP file, potentially leading to a crash or information disclosure.

Source: NVD

References

Related CVEs

Same CWE

  • CVE-2026-1765 A flaw was found in the `tracker-extract-mp3` component of GNOME localsearch (previously known as tracker-miners) (5.6 MEDIUM)
  • CVE-2026-1764 A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor (5.6 MEDIUM)
  • CVE-2026-12087 Socket versions before 2.041 for Perl have an out-of-bounds heap read
  • CVE-2026-53704 A flaw was found in GStreamer's RealMedia demuxer in the gst-plugins-ugly package (7.1 HIGH)
  • CVE-2026-53703 A vulnerability was found in the GStreamer RealMedia demuxer (gst-plugins-ugly) (7.1 HIGH)