Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-99891.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-99891
Upstream
  • CVE-2026-85150
Published
2026-09-03T13:06:21Z
Modified
2026-09-12T05:28:09Z
Summary
CVE-2026-85150 affecting package gstreamer1-plugins-base 1.20.0-3
Details

A NULL pointer dereference flaw was found in GStreamer's RTSP support library. The vulnerability occurs while parsing an Authorization or WWW-Authenticate header that uses Digest authentication. Specially crafted whitespace placement around a parameter's terminator can cause an internal length calculation to underflow, leading to a crash of the process parsing the header. On an RTSP server this can be triggered by a remote, unauthenticated attacker sending a single malformed request when the server has authentication enabled; the same flaw can also be triggered against an RTSP client by a malicious or compromised RTSP server. Successful exploitation results in a denial of service (application crash) and has no confirmed impact on confidentiality or integrity.

References

Affected packages

Azure Linux:3 / gstreamer1-plugins-base

Package

Name
gstreamer1-plugins-base
Purl
pkg:rpm/azure-linux/gstreamer1-plugins-base

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
1.20.0-3

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-99891.json"