CVE-2026-3083Disclosure(gstreamer / gstreamer)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch gstreamer gstreamer systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

GStreamer rtpqdm2depay Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the processing of X-QDM RTP payload elements. When parsing the packetid element, the process does not properly validate user-supplied data, which can result in a write past the end of an allocated array. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28850.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-129CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • gstreamer

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 2 mentions (2026-03-16); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
gstreamer

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-03-09: 1Mentions · 2026-03-13: 1Mentions · 2026-03-16: 2Mentions · 2026-03-18: 1Patch / Workaround · 2026-03-16: 1Technical Details · 2026-03-09: 1Technical Details · 2026-03-13: 1Technical Details · 2026-03-16: 2Technical Details · 2026-03-18: 103-0903-1303-1603-18
Signal classification2 categories
Disclosure
480.0%
Patch
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-091
Disclosure1
2026-03-131
Disclosure1
2026-03-162
Disclosure1Patch1
2026-03-181
Disclosure1
Full discourse5 posts
  • TheZDIBugs@TheZDIBugs
    Disclosure

    [ZDI-26-166|CVE-2026-3083] GStreamer rtpqdm2depay Out-Of-Bounds Write Remote Code Execution Vulnerability (CVSS 8.8) https://www.zerodayinitiative.com/advisories/ZDI-26-166/

    Post summary

    The advisory announces a new GStreamer flaw (CVE‑2026‑3083) that permits a remote code execution via an out‑of‑bounds write, with a CVSS score of 8.8, but no PoC, exploit code, patch, or evidence of active exploitation is presented in the brief text.

    000651.1K
    5.4K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: 10 Critical #RCE vulnerabilities patched in #GStreamer! Highlights: CVE-2026-3083 & CVE-2026-3085 CVSS: 8.8. Network-exploitable Heap Overflow & OOB Write in RTP stream parsing. #Patch #Patch #Patch

    Post summary

    Ten critical RCE vulnerabilities, including CVE-2026-3083 and CVE-2026-3085, have been patched in GStreamer, identified as heap overflow and out-of-bounds write issues with a CVSS score of 8.8.

    00001293
    7.2K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-3083 - High GStreamer rtpqdm2depay Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Int... https://www.thehackerwire.com/vulnerability/CVE-2026-3083/ https://t.co/XBl7RVwfA1

    Post summary

    The post discloses a high‑severity out‑of‑bounds write leading to remote code execution in GStreamer rtpqdm2depay, but provides no PoC, exploit code, or evidence of active exploitation.

    0000031
    138 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-3083: HIGH] Vulnerability Alert: GStreamer rtpqdm2depay has a critical Out-Of-Bounds Write flaw, allowing remote attackers to execute arbitrary code. Stay vigilant against potential cyber threats!#cve,CVE-2026-3083,#cybersecurity https://cvefind.com/CVE-2026-3083

    Post summary

    The post alerts users to an OOBW vulnerability in GStreamer’s rtpqdm2depay enabling remote code execution, but does not provide a PoC, exploit, or patch details.

    0000038
    601 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3083 GStreamer rtpqdm2depay Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected install… https://www.cve.org/CVERecord?id=CVE-2026-3083

    Post summary

    The tweet announces CVE‑2026‑3083 as an out-of-bounds write leading to remote code execution in GStreamer, with no PoC, exploit, or patch details provided.

    00000199
    56.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgstreamergstreamer---

Explore more