CVE-2026-46470 Details
Description
An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's qtdemux_audio_caps function does not sufficiently validate atom data before performing division operations, leading to denial of service due to integer division by zero.
A denial-of-service vulnerability has been identified in GStreamer gst-plugins-good versions prior to 1.28.2. The issue arises in the isomp4 plugin's qtdemux_audio_caps function, which improperly validates atom data when parsing MP4 audio tracks. This lack of validation allows for division operations to be performed on zero values, leading to integer division by zero and causing a crash.
Users can upgrade to GStreamer gst-plugins-good version 1.28.2 to address this vulnerability. Instructions for downloading this version are available on the GStreamer website.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-369 | Divide By Zero | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| freedesktop gst-plugins-good | < 1.28.2 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 19, 2026 | Initial Analysis | [email protected] |
| May 14, 2026 | New CVE Received | [email protected] |