漏洞概述 漏洞编号: CVE-2026-53705 漏洞标题: GStreamer: Heap buffer overflow in WavPack decoder via integer overflow 状态: NEW 优先级: high 严重程度: high 报告时间: 2026-06-10 16:16 UTC by OSIDB Bzreport 修改时间: 2026-06-15 16:38 UTC 影响范围 产品: Security Response 组件: vulnerability 硬件: All 操作系统: Linux 版本: unspecified 环境: 未指定 最后关闭: 未指定 Embargoed: 未指定 修复方案 修复版本: 未指定 关闭原因: 未指定 CC列表: 3 users (show) 依赖项: 2468546 阻塞项: depends on / blocked 详细描述 描述: GStreamer WavPack decoder heap buffer overflow via integer overflow. In (gstwavpackdec.c), the allocation uses unchecked 32-bit arithmetic. With and stereo, the multiplication wraps to 8 bytes; then writes ~4 GB past the allocation. Affects 64-bit PML (arithmetic is 32-bit before size_t promotion). Fix pending in GStreamer 1.20.4. Reported via PSIRTSGPT-8879 by Seung Min Shin. 附件 附件名称: 2026-06-10 16:16:05 UTC 描述: 同上详细描述 备注 需要登录才能评论或对此漏洞进行更改。