CVE-2026-19389

Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdemux) when parsing header objects from crafted ASF, WMV, or WMA files. Insufficient validation of attacker-controlled length and size values can bypass bounds checks and cause out-of-bounds heap reads. This can result in application crash, denial of service, or limited information disclosure when untrusted media is processed.

Scoring

Severity
HIGH
CVSS base score
7.1
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
EPSS probability
0.34%
CWE
CWE-190
Published
2026-08-10
Last modified
2026-09-16

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs