REDHAT-BUG-2491321: Medium severity GStreamer gst-plugins-bad vulnerability
A 1-byte heap out-of-bounds read vulnerability exists in the gsth264parseprocessnal() function in subprojects/gst-plugins-bad/gst/videoparsers/gsth264parse.c. The function processes H.264 NAL units including GSTH264NALSLICEEXT (NAL type 20) for MVC/SVC extension slices. At line 1132, the code dereferences (nalu->data + nalu->offset + nalu->headerbytes) to check the firstmbinslice flag without first verifying that nalu->size > nalu->headerbytes. For extension slice types, headerbytes is set to 4 (1 byte base + 3 bytes extension header per gsth264parser.c:243). A malformed NAL unit with exactly size==4 passes the minimum size check (size >= 2 at line 999) but triggers a 1-byte read at offset 4, which is beyond the allocated buffer. The same bounds check pattern is correctly implemented in gsth264parsecollectnal() at line 1259 with if (nalu->size > nalu->headerbytes). The vulnerability affects GStreamer 1.x versions (tested against git version 1.29.1.1). Upstream maintainer Sebastian Droege confirmed the vulnerability via GitLab work item 5108. Reported by Dr. Faruk Kazi, Ramesh Adhikari, and Ariba Afroz from CoE-CNDS Lab, VJTI, Mumbai, India. PSIRT Ticket: PSIRTSUPT-17585.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Before dereferencing *(nalu->data + nalu->offset + nalu->header_bytes) (around line 1132) add a check that nalu->size > nalu->header_bytes (e.g. if (nalu->size > nalu->header_bytes) { /* existing access */ }). Mirror the bounds check used in gst_h264_parse_collect_nal() at line 1259 to ensure the first_mb_in_slice access cannot read past the NAL unit buffer.
gst-plugins-bad/gst/videoparsers/gsth264parse.c :: gst_h264_parse_process_nal() nalu->size > nalu->header_bytes bounds check = add/enable
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2491321?
The severity of REDHAT-BUG-2491321 is medium, rated as 4.
How do I fix REDHAT-BUG-2491321?
To fix REDHAT-BUG-2491321, update your GStreamer gst-plugins-bad package to the latest version that addresses the vulnerability.
What does REDHAT-BUG-2491321 affect?
REDHAT-BUG-2491321 affects the gst_h264_parse_process_nal() function found in the GStreamer gst-plugins-bad package.
What is the nature of the vulnerability in REDHAT-BUG-2491321?
The nature of the vulnerability in REDHAT-BUG-2491321 is a 1-byte heap out-of-bounds read.
When was REDHAT-BUG-2491321 published?
REDHAT-BUG-2491321 was published on June 22, 2026.