Skip to content

CVE-2026-59692 on CTRL-OS 26.05

Aliases: CVE-2026-59692

Packages: gst_all_1.gst-plugins-bad

Status: Plausible

Advisory Information

A stack buffer overflow vulnerability was found in GStreamer's DTLS plugin. During a DTLS handshake, the peer certificate Subject Distinguished Name is printed into a fixed-size 2048-byte stack buffer without bounds checking. A remote unauthenticated attacker can send a certificate with an oversized Subject DN that exceeds the buffer, causing a stack buffer overflow and process crash, resulting in denial of service.

Updates

2026-08-24 11:16 CEST

Metadata changes:

  • Status for package gst_all_1.gst-plugins-bad: “Plausible

(Amended on: 2026-08-24 11:19 CEST)

2026-08-24 11:07 CEST

Metadata changes:

  • Status for package gst_all_1.gst-plugins-bad: “New

(Amended on: 2026-08-24 11:08 CEST)