CVE-2024-47600

Name
CVE-2024-47600
Description
GStreamer is a library for constructing graphs of media-handling components. An OOB-read vulnerability has been detected in the format_channel_mask function in gst-discoverer.c. The vulnerability affects the local array position, which is defined with a fixed size of 64 elements. However, the function gst_discoverer_audio_info_get_channels may return a guint channels value greater than 64. This causes the for loop to attempt access beyond the bounds of the position array, resulting in an OOB-read when an index greater than 63 is used. This vulnerability can result in reading unintended bytes from the stack. Additionally, the dereference of value->value_nick after the OOB-read can lead to further memory corruption or undefined behavior. This vulnerability is fixed in 1.24.10.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/8034.patch
MISC https://gstreamer.freedesktop.org/security/sa-2024-0018.html
CONFIRM https://securitylab.github.com/advisories/GHSL-2024-248_Gstreamer/

Match rules

CPE URI Source package Min version Max version
gstreamer >= 0 < 1.24.10
cpe:2.3:a:gstreamer_project:gstreamer:*:*:*:*:*:*:*:* gstreamer >= None < 1.24.10

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
gst-plugins-base edge-main 1.24.10-r0 Krassy Boykinov <kboykinov@teamcentrixx.com> fixed
gst-plugins-base 3.21-main 1.24.10-r0 Krassy Boykinov <kboykinov@teamcentrixx.com> fixed
gstreamer edge-main 1.24.9-r0 Krassy Boykinov <kboykinov@teamcentrixx.com> possibly vulnerable
gst-plugins-base 3.20-main 1.24.10-r0 Natanael Copa <ncopa@alpinelinux.org> fixed