CVE Tools

CVE-2026-1940

Gstreamer: incomplete fix of cve-2026-1940

Published: Mar 23, 2026Updated: May 4, 2026 Sources: CVE List NVDCWE-125
5.1CVSSMEDIUM

Description

An incomplete fix for CVE-2024-47778 allows an out-of-bounds read in gst_wavparse_adtl_chunk() function. The patch added a size validation check lsize + 8 > size, but it does not account for the GST_ROUND_UP_2(lsize) used in the actual offset calculation. When lsize is an odd number, the parser advances more bytes than validated, causing OOB read.

CVSS Vector Breakdown

AV:LAC:LPR:NUI:NS:UC:NI:LA:L
Exploitability
AV:LAttack Vector
Local
AC:LAttack Complexity
Low
PR:NPrivileges Required
None
UI:NUser Interaction
None
Scope
S:UScope
Unchanged
Impact
C:NConfidentiality
None
I:LIntegrity
Low
A:LAvailability
Low

Weaknesses

Affected Products

freedesktoposs-projectOSS Librariesaka freedesktop.org
gstreameross-projectOSS Librariesaka good plug-ins, plug-ins
debianoss-projectGBOperating Systemsaka debian gnu/linux
redhatcommercialUSOperating Systemsaka red hat
red hatcommercialUSOperating Systemsaka red hat
and 4 more affected products View all →

Attack Graph

Products CVE Techniques Tactics

Click technique nodes to view MITRE ATT&CK details. Scroll to zoom, drag to pan.

Exploitability

Official Patch Available

MITRE ATT&CK

1 technique
Collection
View detailed technique mapping

References

and 2 more references View all →

Timeline

Published
Mar 23, 2026
Last Updated
May 4, 2026

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2026-1940 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows