216.73.217.22

CVE-2026-46469

· Published 14/05/2026 18:16 · Modified 14/05/2026 18:24

Labels: CVE-2026-46469 2026-05-14CVE-2026-46469CWE-369[email protected]

Essential information

Published
14/05/2026 18:16
Modified
14/05/2026 18:24
Author
Creator
CVSS
4.0 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

CVSS metrics

Description

An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's qtdemux_parse_trak function does not sufficiently validate atom data before performing division operations, leading to denial of service due to integer division by zero.

NVD status

Status
Undergoing Analysis — CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
gstreamer / gst-plugins-good cpe:2.3:a:gstreamer:gst-plugins-good:<1.28.2:*:*:*:*:*:*:*

References