CVE-2026-85150
Reported by redhat · Published September 3, 2026
A NULL pointer dereference flaw was found in GStreamer's RTSP support library. The vulnerability occurs while parsing an Authorization or WWW-Authenticate header that uses Digest authentication. Specially crafted whitespace placement around a parameter's terminator can cause an internal length calculation to underflow, leading to a crash of the process parsing the header. On an RTSP server this can be triggered by a remote, unauthenticated attacker sending a single malformed request when the server has authentication enabled; the same flaw can also be triggered against an RTSP client by a malicious or compromised RTSP server. Successful exploitation results in a denial of service (application crash) and has no confirmed impact on confidentiality or integrity.
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | 0:1.26.7-2.el10_2.2 |
| Red Hat | Red Hat Enterprise Linux 8 | 0:1.16.1-7.el8_10 |
| Red Hat | Red Hat Enterprise Linux 7 | |
| Red Hat | Red Hat Enterprise Linux 9 | |
| Red Hat | Red Hat Enterprise Linux 7 | |
| Red Hat | Red Hat Enterprise Linux 8 | 0:1.16.1-7.el8_10 |
| Red Hat | Red Hat Enterprise Linux 9 | |
| Red Hat | Red Hat Enterprise Linux 10 | 0:1.26.7-2.el10_2.2, 0:1.26.7-2.el10_2.2 |
Timeline
- Sep 3, 2026 Coalition ESS Score
- Sep 3, 2026 CVE Published
- Sep 4, 2026 EPSS Score
- Sep 9, 2026 EPSS Score
- Sep 11, 2026 Distribution Patch
- Sep 11, 2026 Security Advisory
- Sep 12, 2026 EPSS Score
- Sep 14, 2026 EPSS Score
- Sep 14, 2026 Distribution Patch
- Sep 14, 2026 Security Advisory
- Sep 16, 2026 EPSS Score
- Sep 18, 2026 EPSS Score
References
- RHSA-2026:66460 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:67145 vendor-advisoryx_refsource_REDHAT
- vdb-entryx_refsource_REDHAT
- RHBZ#2527936 issue-trackingx_refsource_REDHAT