VDB

GCVE-VVD-MAGEIA-2021-334

GCVE-VVD-MAGEIA-2021-334
Advisory Published
Vulnetix · Advisory published July 10, 2021
GStreamer before 1.18.4 may perform an out-of-bounds read when handling certain ID3v2 tags (CVE-2021-3522). Overflows in AVC/HEVC NAL unit length calculations, which would lead to allocating infinite amounts of small memory blocks until OOM and could potentially also lead to memory corruptions.

Affected Products

VendorProductVersionsPlatforms
Mageiagstreamer1.0-plugins-base0 (affected), 1.16.0-2.1.mga7 (unaffected)
Mageiagstreamer1.0-plugins-base0 (affected), 1.18.3-1.1.mga8 (unaffected)
Mageiagstreamer1.0-plugins-bad0 (affected), 1.18.3-1.1.mga8 (unaffected), 0 (affected), 1.18.3-1.1.mga8.tainted (unaffected)
Mageiagstreamer1.0-plugins-bad0 (affected), 1.16.0-1.2.mga7 (unaffected), 0 (affected), 1.16.0-1.2.mga7.tainted (unaffected)

Browse GCVE Records

100 records in the GCVE database · Updated April 16, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›