CVE-2026-18649 Details
Description
A flaw was found in the GStreamer gst-plugins-good package. The rtph264depay and rtph265depay RTP depayloader elements do not enforce a maximum size limit on the reassembly buffer used during fragmented RTP packet processing. A remote, unauthenticated attacker can send a continuous stream of RTP fragments without ever transmitting an end-of-fragment marker, causing the reassembly buffer to grow without bound until process memory is exhausted. This results in a denial of service through process termination.
A denial-of-service vulnerability has been identified in the GStreamer gst-plugins-good package, specifically within the rtph264depay and rtph265depay RTP depayloader elements. These components fail to impose a maximum size limit on the reassembly buffer used when processing fragmented RTP packets. As a result, a remote, unauthenticated attacker can send an endless stream of RTP fragments without including an end-of-fragment marker, causing the reassembly buffer to expand indefinitely until the process runs out of memory. This unbounded memory growth leads to process termination.
Users can mitigate this vulnerability by employing SRTP or DTLS-SRTP to authenticate RTP packets before they reach the depayloaders. Alternatively, firewall rules can be used to restrict RTP traffic to trusted sources. Another option is to disable the RTP plugin entirely or prevent the affected depayloaders from being automatically selected in GStreamer pipelines.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-770 | Allocation of Resources Without Limits or Throttling | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
15 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 23, 2026 | CVE Modified | [email protected] |
| Sep 23, 2026 | CVE Modified | [email protected] |
| Sep 22, 2026 | CVE Modified | [email protected] |
| Sep 21, 2026 | CVE Modified | [email protected] |
| Sep 17, 2026 | CVE Modified | [email protected] |
| Sep 9, 2026 | CVE Modified | [email protected] |
| Sep 9, 2026 | CVE Modified | [email protected] |
| Sep 1, 2026 | CVE Modified | [email protected] |
| Aug 31, 2026 | CVE Modified | [email protected] |
| Aug 19, 2026 | CVE Modified | [email protected] |
| Aug 17, 2026 | CVE Modified | [email protected] |
| Aug 11, 2026 | CVE Modified | [email protected] |
| Aug 11, 2026 | CVE Modified | [email protected] |
| Aug 6, 2026 | CVE Modified | CISA-ADP |
| Aug 6, 2026 | New CVE Received | [email protected] |