PT-2026-38834 · Bitnami · Jre
Published
2026-05-08
·
Updated
2026-05-08
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
GStreamer is a library for constructing graphs of media-handling components. An integer underflow has been detected in extract cc from data function within qtdemux.c. In the FOURCC c708 case, the subtraction atom length - 8 may result in an underflow if atom length is less than 8. When that subtraction underflows, *cclen ends up being a large number, and then cclen is passed to g memdup2 leading to an out-of-bounds (OOB) read. This vulnerability is fixed in 1.24.10.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jre