VDB

CVE-2026-19387

CVE-2026-19387 PUBLISHED CVSS 7.6 HIGH

Reported by redhat · Published August 10, 2026

A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio. Insufficient validation of the per-block sample count for multi-channel streams allows a crafted WAV file to cause writes beyond the allocated output buffer. This can lead to application crash, denial of service, memory corruption, or potentially arbitrary code execution when untrusted media is processed.

Risk Scores

CVSS 3.1
7.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H

Affected Products

VendorProductVersions
Red HatRed Hat Enterprise Linux 100:1.26.7-2.el10_2.7
Red HatRed Hat Enterprise Linux 10.0 Extended Update Support0:1.24.11-3.el10_0.7
Red HatRed Hat Enterprise Linux 7 Extended Lifecycle Support0:1.10.4-8.el7_9
Red HatRed Hat Enterprise Linux 80:1.16.1-9.el8_10.2
Red HatRed Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support0:1.16.1-4.el8_4.5
Red HatRed Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On0:1.16.1-4.el8_4.5
Red HatRed Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support0:1.16.1-4.el8_6.5
Red HatRed Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On0:1.16.1-4.el8_6.5
Red HatRed Hat Enterprise Linux 8.8 Telecommunications Update Service0:1.16.1-4.el8_8.5
Red HatRed Hat Enterprise Linux 8.8 Update Services for SAP Solutions0:1.16.1-4.el8_8.5
Red HatRed Hat Enterprise Linux 90:1.22.12-7.el9_8.4
Red HatRed Hat Enterprise Linux 90:1.22.12-6.el9_8.2
Red HatRed Hat Enterprise Linux 9.2 Update Services for SAP Solutions0:1.18.4-9.el9_2.6
Red HatRed Hat Enterprise Linux 9.4 Update Services for SAP Solutions0:1.22.1-6.el9_4.7
Red HatRed Hat Enterprise Linux 9.6 Extended Update Support0:1.22.12-5.el9_6.7
Red HatRed Hat Enterprise Linux 9.6 Extended Update Support0:1.22.12-5.el9_6.7, 0:1.22.12-5.el9_6.7, 0:1.22.12-5.el9_6.7
Red HatRed Hat Enterprise Linux 80:1.16.1-9.el8_10.2, 0:1.16.1-9.el8_10.2, 0:1.16.1-9.el8_10.2
Red HatRed Hat Enterprise Linux 90:1.22.12-6.el9_8.2, 0:1.22.12-6.el9_8.2, 0:1.22.12-6.el9_8.2
Red HatRed Hat Enterprise Linux 9.2 Update Services for SAP Solutions0:1.18.4-9.el9_2.6, 0:1.18.4-9.el9_2.6, 0:1.18.4-9.el9_2.6
Red HatRed Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support0:1.16.1-4.el8_4.5, 0:1.16.1-4.el8_4.5

…and 11 more

Timeline

  • Aug 10, 2026 Coalition ESS Score
  • Aug 10, 2026 CVE Published
  • Aug 16, 2026 Security Advisory
  • Aug 18, 2026 Distribution Patch
  • Aug 18, 2026 Security Advisory
  • Aug 19, 2026 Distribution Patch
  • Aug 19, 2026 Security Advisory
  • Aug 24, 2026 EPSS Score
  • Aug 25, 2026 Distribution Patch
  • Aug 26, 2026 Distribution Patch
  • Aug 30, 2026 EPSS Score
  • Aug 30, 2026 Distribution Patch

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›