CVE-2026-19387Disclosure

LOWCVSS 7.6 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio. Insufficient validation of the per-block sample count for multi-channel streams allows a crafted WAV file to cause writes beyond the allocated output buffer. This can lead to application crash, denial of service, memory corruption, or potentially arbitrary code execution when untrusted media is processed.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-10: 2Technical Details · 2026-08-10: 108-10
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-19387 A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio. Insufficient validation of the… https://www.cve.org/CVERecord?id=CVE-2026-19387

    Post summary

    A heap out‑of‑bounds write vulnerability has been disclosed in the GStreamer adpcmdec element used for IMA/DVI ADPCM audio decoding.

    00010973
    57.9K followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    The severity is increased for this new vulnerability affecting Red Hat Enterprise Linux (CVE-2026-19387) https://vuldb.com/vuln/387289

    Post summary

    The post notes that the severity level of CVE-2026-19387 affecting Red Enterprise Linux has been increased, providing a link to a vulnerability database entry, but offers no further technical details or exploit information.

    00000126
    2.3K followersView on X

Explore more