VDB
CVE-2026-19387
CVE-2026-19387
PUBLISHED
CVSS 7.6 HIGH
Reported by redhat · Published August 10, 2026
A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio. Insufficient validation of the per-block sample count for multi-channel streams allows a crafted WAV file to cause writes beyond the allocated output buffer. This can lead to application crash, denial of service, memory corruption, or potentially arbitrary code execution when untrusted media is processed.
Risk Scores
CVSS 3.1
7.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | 0:1.26.7-2.el10_2.7 |
| Red Hat | Red Hat Enterprise Linux 10.0 Extended Update Support | 0:1.24.11-3.el10_0.7 |
| Red Hat | Red Hat Enterprise Linux 7 Extended Lifecycle Support | 0:1.10.4-8.el7_9 |
| Red Hat | Red Hat Enterprise Linux 8 | 0:1.16.1-9.el8_10.2 |
| Red Hat | Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | 0:1.16.1-4.el8_4.5 |
| Red Hat | Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | 0:1.16.1-4.el8_4.5 |
| Red Hat | Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | 0:1.16.1-4.el8_6.5 |
| Red Hat | Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On | 0:1.16.1-4.el8_6.5 |
| Red Hat | Red Hat Enterprise Linux 8.8 Telecommunications Update Service | 0:1.16.1-4.el8_8.5 |
| Red Hat | Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | 0:1.16.1-4.el8_8.5 |
| Red Hat | Red Hat Enterprise Linux 9 | 0:1.22.12-7.el9_8.4 |
| Red Hat | Red Hat Enterprise Linux 9 | 0:1.22.12-6.el9_8.2 |
| Red Hat | Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | 0:1.18.4-9.el9_2.6 |
| Red Hat | Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions | 0:1.22.1-6.el9_4.7 |
| Red Hat | Red Hat Enterprise Linux 9.6 Extended Update Support | 0:1.22.12-5.el9_6.7 |
| Red Hat | Red Hat Enterprise Linux 9.6 Extended Update Support | 0:1.22.12-5.el9_6.7, 0:1.22.12-5.el9_6.7, 0:1.22.12-5.el9_6.7 |
| Red Hat | Red Hat Enterprise Linux 8 | 0:1.16.1-9.el8_10.2, 0:1.16.1-9.el8_10.2, 0:1.16.1-9.el8_10.2 |
| Red Hat | Red Hat Enterprise Linux 9 | 0:1.22.12-6.el9_8.2, 0:1.22.12-6.el9_8.2, 0:1.22.12-6.el9_8.2 |
| Red Hat | Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | 0:1.18.4-9.el9_2.6, 0:1.18.4-9.el9_2.6, 0:1.18.4-9.el9_2.6 |
| Red Hat | Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | 0:1.16.1-4.el8_4.5, 0:1.16.1-4.el8_4.5 |
…and 11 more
Timeline
- Aug 10, 2026 Coalition ESS Score
- Aug 10, 2026 CVE Published
- Aug 16, 2026 Security Advisory
- Aug 18, 2026 Distribution Patch
- Aug 18, 2026 Security Advisory
- Aug 19, 2026 Distribution Patch
- Aug 19, 2026 Security Advisory
- Aug 24, 2026 EPSS Score
- Aug 25, 2026 Distribution Patch
- Aug 26, 2026 Distribution Patch
- Aug 30, 2026 EPSS Score
- Aug 30, 2026 Distribution Patch
References
- RHSA-2026:55433 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:55865 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:56521 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:65122 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:65123 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:65124 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:66406 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:66407 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:67151 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:67844 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:67861 vendor-advisoryx_refsource_REDHAT
- vdb-entryx_refsource_REDHAT
- RHBZ#2513015 issue-trackingx_refsource_REDHAT