DEBIAN-CVE-2026-19387

Source
https://security-tracker.debian.org/tracker/CVE-2026-19387
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-19387.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-19387
Upstream
  • CVE-2026-19387
Published
2026-08-10T03:16:40Z
Modified
2026-09-19T23:00:07Z
Severity
  • 7.6 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H CVSS Calculator
Summary
[none]
Details

A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio. Insufficient validation of the per-block sample count for multi-channel streams allows a crafted WAV file to cause writes beyond the allocated output buffer. This can lead to application crash, denial of service, memory corruption, or potentially arbitrary code execution when untrusted media is processed.

References

Affected packages

Debian:12 / gst-plugins-bad1.0

Package

Name
gst-plugins-bad1.0
Purl
pkg:deb/debian/gst-plugins-bad1.0?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.22.0-4
1.22.0-4+deb12u1
1.22.0-4+deb12u2
1.22.0-4+deb12u3
1.22.0-4+deb12u4
1.22.0-4+deb12u5
1.22.0-4+deb12u6
1.22.0-4+deb12u7
1.22.1-1
1.22.3-1
1.22.3-2
1.22.4-1
1.22.7-1
1.22.8-1
1.22.9-1
1.22.9-2
1.22.10-1
1.23.1-1
1.23.2-1
1.23.90-1
1.24.0-1
1.24.1-1
1.24.1-2
1.24.1-3
1.24.1-4
1.24.2-1
1.24.2-2
1.24.2-3
1.24.2-4
1.24.3-1
1.24.4-1
1.24.4-2
1.24.5-1
1.24.6-1
1.24.7-1
1.24.8-1
1.24.8-2
1.24.9-1
1.24.10-1
1.24.10-2
1.24.10-2+hurd.1
1.24.10-3
1.24.11-1
1.24.11-2
1.24.11-3
1.24.12-1
1.24.12-2
1.24.12-3
1.25.1-1
1.25.1-2
1.25.1-3
1.25.50-1
1.25.90-1
1.25.90-2
1.25.90-3
1.26.0-1
1.26.1-1
1.26.2-1
1.26.2-2
1.26.2-3
1.26.3-1
1.26.4-1
1.26.5-1
1.26.5-2
1.26.6-1
1.26.6-2
1.26.6-3
1.26.6-4
1.26.6-5
1.26.7-1
1.26.7-2
1.26.8-1
1.26.9-1
1.26.10-1
1.26.10-2
1.27.1-1
1.27.2-1
1.27.50-1
1.27.90-1
1.27.90-2
1.27.90-3
1.28.0-1
1.28.1-1
1.28.1-2
1.28.1-3
1.28.2-1
1.28.2-2
1.28.3-1
1.28.4-1
1.28.5-1
1.28.5-2
1.28.6-1
1.28.7-1
1.28.7-2
1.29.1-1
1.29.2-1
1.29.2-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-19387.json"

Debian:13 / gst-plugins-bad1.0

Package

Name
gst-plugins-bad1.0
Purl
pkg:deb/debian/gst-plugins-bad1.0?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.26.2-3+deb13u3

Affected versions

1.*
1.26.2-3
1.26.2-3+deb13u1
1.26.2-3+deb13u2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-19387.json"

Debian:14 / gst-plugins-bad1.0

Package

Name
gst-plugins-bad1.0
Purl
pkg:deb/debian/gst-plugins-bad1.0?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.28.6-1

Affected versions

1.*
1.26.2-3
1.26.3-1
1.26.4-1
1.26.5-1
1.26.5-2
1.26.6-1
1.26.6-2
1.26.6-3
1.26.6-4
1.26.6-5
1.26.7-1
1.26.7-2
1.26.8-1
1.26.9-1
1.26.10-1
1.26.10-2
1.27.1-1
1.27.2-1
1.27.50-1
1.27.90-1
1.27.90-2
1.27.90-3
1.28.0-1
1.28.1-1
1.28.1-2
1.28.1-3
1.28.2-1
1.28.2-2
1.28.3-1
1.28.4-1
1.28.5-1
1.28.5-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-19387.json"