CVE-2026-52718
CVE-2026-52718: 1 tracked advisory record across Red Hat. Compare source-reported impact, fixes and remediation.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Red Hat
1 advisory- Advisory severityMedium6.5
Medium [CVE-2026-52718] denial of service via av1 tile_list_obu parser byte/bit confusion
CVE-2026-52718Source published Source updated
A denial of service vulnerability was found in GStreamer's AV1 codec parser in gst-plugins-bad. The gst_av1_parser_parse_tile_list_obu() function passes a byte count to a bit-reader API that expects a bit count, causing parser desynchronization. A remote attacker could trick a user into opening a specially crafted AV1 media file, triggering an assertion abort and causing the application to crash. The flaw allows a deterministic application crash when processing specially crafted AV1 media files due to a byte/bit unit confusion in gst_av1_parser_parse_tile_list_obu(). The impact is limited to availability since the assertion abort terminates the process immediately with no path to code execution or information disclosure. Red Hat products utilizing GStreamer for multimedia processing are…
- Affected products in this advisory
- Red Hat Enterprise Linux 10.0 Extended Update Support
- Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
- Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions
- Red Hat Enterprise Linux 9.6 Extended Update Support
3 more entries in the full advisory.
- Source-reported affected versions
- Affected-version details not available in this record.
- Source-reported fixed versions
- gstreamer1-plugins-bad-free-0:1.26.7-2.el10_2.4
- gstreamer1-plugins-bad-free-0:1.24.11-3.el10_0.4
- gstreamer1-plugins-bad-free-0:1.22.12-7.el9_8.1
- gstreamer1-plugins-bad-free-0:1.18.4-9.el9_2.3
8 more entries in the full advisory.
- Mitigation guidance
- Red Hat is not aware of a practical temporary workaround that fully mitigates this issue or meets Red Hat Product Security's standards for usability, deployment, applicability, or stability.
Android app · Google Play
Monitor future Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.