PT-2024-9625 · Gstreamer+10 · Gstreamer+10

Antonio Morales

+1

·

Published

2024-10-02

·

Updated

2025-10-07

·

CVE-2024-47615

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GStreamer versions prior to 1.24.10
Description The issue is related to a function gst parse vorbis setup packet in the GStreamer multimedia framework, which is associated with a buffer overflow in memory. This can be exploited by a remote attacker to cause a denial of service. The vulnerability is due to an out-of-bounds write in the gst parse vorbis setup packet function within vorbis parse.c, where an integer size is read from the input file without proper validation, potentially exceeding the fixed size of the pad->vorbis mode sizes array. This can overwrite up to 380 bytes of memory beyond the boundaries of the array, affecting adjacent memory.
Recommendations For versions prior to 1.24.10, update to version 1.24.10 to patch this issue and secure your system. As a temporary workaround, consider restricting the use of the gst parse vorbis setup packet function until a patch is available.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:11123
ALSA-2024:11345
ALSA-2024_11123
ALSA-2024_11345
ALT-PU-2025-2299
ALT-PU-2025-7573
AZL-54309
AZL-54365
AZL-62405
BDU:2024-11337
CESA-2024_11345
CVE-2024-47615
DLA-3999-1
DSA-5831-1
INFSA-2024_11123
INFSA-2024_11345
OESA-2024-2563
OPENSUSE-SU-2024:14577-1
OPENSUSE-SU-2025_0054-1
OPENSUSE-SU-2025_0065-1
OPENSUSE-SU-2025_0069-1
RHSA-2024:11117
RHSA-2024:11118
RHSA-2024:11120
RHSA-2024:11123
RHSA-2024:11130
RHSA-2024:11141
RHSA-2024:11142
RHSA-2024:11143
RHSA-2024:11344
RHSA-2024:11345
RHSA-2024_11123
RHSA-2024_11345
RLSA-2024:11123
RLSA-2024:11345
SUSE-SU-2025:0052-1
SUSE-SU-2025:0054-1
SUSE-SU-2025:0065-1
SUSE-SU-2025:0069-1
SUSE-SU-2025:02020-1
SUSE-SU-2025:20134-1
SUSE-SU-2025:20241-1
SUSE-SU-2025_02020-1
USN-7175-1
USN-7807-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Gstreamer
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu