CVE-2026-19387
A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio. Insufficient validation of the per-block sample count for multi-channel streams allows a crafted WAV file to cause writes beyond the allocated output buffer. This can lead to application crash, denial of service, memory corruption, or potentially arbitrary code execution when untrusted media is processed.
CSIRTS triage
- What
- Multiple security vulnerabilities in GStreamer plugins for codecs and demuxers allow denial of service or arbitrary code execution via malformed media files.
- Who is affected
- Systems using GStreamer for media playback or processing; any application that opens untrusted media files.
- Urgency
- High; arbitrary code execution is possible if a crafted media file is opened.
- Action
- Apply DSA-6458-1 security update for gst-plugins-bad1.0.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-19387
Get an email if CVE-2026-19387 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all EPSS-scored CVEs.
Advisory coverage (2)
- unknownDSA-6458-1 gst-plugins-bad1.0 - security updatedebian · 2026-08-21
- highCVE-2026-19387: A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec e…nvd · 2026-08-10
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-19387)