OESA-2025-2437

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2025-2437
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2025-2437.json
JSON Data
https://api.osv.dev/v1/vulns/OESA-2025-2437
Upstream
Published
2025-10-17T11:09:32Z
Modified
2026-08-18T01:19:14Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
gstreamer1 security update
Details

GStreamer1 implements a framework that allows for processing and encoding of multimedia sources in a manner similar to a shell pipeline.

Security Fix(es):

GStreamer is a library for constructing graphs of media-handling components. An integer underflow has been detected in the function qtdemux_parse_theora_extension within qtdemux.c. The vulnerability occurs due to an underflow of the gint size variable, which causes size to hold a large unintended value when cast to an unsigned integer. This 32-bit negative value is then cast to a 64-bit unsigned integer (0xfffffffffffffffa) in a subsequent call to gst_buffer_new_and_alloc. The function gst_buffer_new_allocate then attempts to allocate memory, eventually calling _sysmem_new_block. The function _sysmem_new_block adds alignment and header size to the (unsigned) size, causing the overflow of the 'slice_size' variable. As a result, only 0x89 bytes are allocated, despite the large input size. When the following memcpy call occurs in gst_buffer_fill, the data from the input file will overwrite the content of the GstMapInfo info structure. Finally, during the call to gst_memory_unmap, the overwritten memory may cause a function pointer hijack, as the mem->allocator->mem_unmap_full function is called with a corrupted pointer. This function pointer overwrite could allow an attacker to alter the execution flow of the program, leading to arbitrary code execution. This vulnerability is fixed in 1.24.10.(CVE-2024-47606)

Database specific
{
    "severity": "Critical"
}
References

Affected packages

openEuler:22.03-LTS-SP4 / gstreamer1

Package

Name
gstreamer1
Purl
pkg:rpm/openEuler/gstreamer1&distro=openEuler-22.03-LTS-SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.19.3-4.oe2203sp4

Ecosystem specific

{
    "aarch64": [
        "gstreamer1-1.19.3-4.oe2203sp4.aarch64.rpm",
        "gstreamer1-debuginfo-1.19.3-4.oe2203sp4.aarch64.rpm",
        "gstreamer1-debugsource-1.19.3-4.oe2203sp4.aarch64.rpm",
        "gstreamer1-devel-1.19.3-4.oe2203sp4.aarch64.rpm"
    ],
    "noarch": [
        "gstreamer1-help-1.19.3-4.oe2203sp4.noarch.rpm"
    ],
    "src": [
        "gstreamer1-1.19.3-4.oe2203sp4.src.rpm"
    ],
    "x86_64": [
        "gstreamer1-1.19.3-4.oe2203sp4.x86_64.rpm",
        "gstreamer1-debuginfo-1.19.3-4.oe2203sp4.x86_64.rpm",
        "gstreamer1-debugsource-1.19.3-4.oe2203sp4.x86_64.rpm",
        "gstreamer1-devel-1.19.3-4.oe2203sp4.x86_64.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2025-2437.json"