CVE-2026-46470 PUBLISHED

Assigner: mitre
Reserved: 14.05.2026 Published: 14.05.2026 Updated: 14.05.2026

An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's qtdemux_audio_caps function does not sufficiently validate atom data before performing division operations, leading to denial of service due to integer division by zero.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CVSS Score: 4

Product Status

Vendor GStreamer
Product Good Plug-ins
Versions Default: unaffected
  • affected from 0 to 1.28.2 (excl.)

References

Problem Types

  • CWE-369 Divide By Zero CWE