CVE-2026-52721 Details
Description
Multiple out-of-bounds read vulnerabilities were found in GStreamer's pcapparse element. Malformed PCAP records can trigger reads beyond buffer boundaries during IPv4/TCP header parsing. This element is primarily used in debugging pipelines, limiting real-world exposure. A local attacker could trick a user into processing a specially crafted PCAP file, potentially leading to a crash or information disclosure.
A moderate out-of-bounds read vulnerability has been identified in the GStreamer pcapparse element, part of the gst-plugins-bad package. This vulnerability arises from improper validation of buffer boundaries when parsing malformed PCAP records, specifically during the interpretation of IPv4 and TCP header fields. The issue allows for memory reads beyond the intended limits, which could lead to crashes or unauthorized information disclosure. The vulnerability is primarily theoretical, as the pcapparse element is mainly used in debugging pipelines rather than standard media playback. However, a local attacker could potentially exploit this by convincing a user to process a specially crafted PCAP file.
A fix for this vulnerability is planned for GStreamer version 1.28.4. Users should update to this version when it becomes available.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 15, 2026 | New CVE Received | [email protected] |