An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's qtdemux_parse_trak function does not sufficiently validate atom data before performing division operations, leading to denial of service due to integer division by zero.
Metrics
Affected Vendors & Products
References
History
Thu, 14 May 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 14 May 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's qtdemux_parse_trak function does not sufficiently validate atom data before performing division operations, leading to denial of service due to integer division by zero. | |
| First Time appeared |
Gstreamer
Gstreamer good Plug-ins |
|
| Weaknesses | CWE-369 | |
| CPEs | cpe:2.3:a:gstreamer:good_plug-ins:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gstreamer
Gstreamer good Plug-ins |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published: 2026-05-14T17:38:44.049Z
Updated: 2026-05-14T18:42:56.086Z
Reserved: 2026-05-14T17:38:43.160Z
Link: CVE-2026-46469
Updated: 2026-05-14T18:42:53.382Z
Status : Awaiting Analysis
Published: 2026-05-14T18:16:50.653
Modified: 2026-05-14T18:24:08.747
Link: CVE-2026-46469
No data.