CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-19387

highCVSS 7.6covered by 2 sourcesfirst seen 2026-08-10
A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio. Insufficient validation of the per-block sample count for multi-channel streams allows a crafted WAV file to cause writes beyond the allocated output buffer. This can lead to application crash, denial of service, memory corruption, or potentially arbitrary code execution when untrusted media is processed.

CSIRTS triage

What
Multiple security vulnerabilities in GStreamer plugins for codecs and demuxers allow denial of service or arbitrary code execution via malformed media files.
Who is affected
Systems using GStreamer for media playback or processing; any application that opens untrusted media files.
Urgency
High; arbitrary code execution is possible if a crafted media file is opened.
Action
Apply DSA-6458-1 security update for gst-plugins-bad1.0.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-19387

Get an email if CVE-2026-19387 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-19387

CVE.org record

Embed the live status

CVE-2026-19387 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-19387 status](https://www.csirts.com/badge/CVE-2026-19387)](https://www.csirts.com/cve/CVE-2026-19387)