CVE-2026-3085Disclosure(gstreamer / gstreamer)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch gstreamer gstreamer systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

GStreamer rtpqdm2depay Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the processing of X-QDM RTP payloads. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28851.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122CWE-1284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • gstreamer

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-16); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
gstreamer

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-03-09: 1Mentions · 2026-03-13: 1Mentions · 2026-03-16: 2Mentions · 2026-03-18: 1Patch / Workaround · 2026-03-16: 1Technical Details · 2026-03-09: 1Technical Details · 2026-03-13: 1Technical Details · 2026-03-16: 2Technical Details · 2026-03-18: 103-0903-1303-1603-18
Signal classification3 categories
Disclosure
360.0%
General
120.0%
Patch
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-091
Disclosure1
2026-03-131
General1
2026-03-162
Disclosure1Patch1
2026-03-181
Disclosure1
Full discourse5 posts
  • TheZDIBugs@TheZDIBugs
    Disclosure

    [ZDI-26-167|CVE-2026-3085] GStreamer rtpqdm2depay Heap-based Buffer Overflow Remote Code Execution Vulnerability (CVSS 8.8) https://www.zerodayinitiative.com/advisories/ZDI-26-167/

    Post summary

    A newly identified GStreamer rtpqdm2depay heap-based buffer overflow Remote Code Execution vulnerability (CVE-2026-3085) with CVSS 8.8 has been disclosed on the ZeroDay Initiative site.

    00021798
    5.4K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: 10 Critical #RCE vulnerabilities patched in #GStreamer! Highlights: CVE-2026-3083 & CVE-2026-3085 CVSS: 8.8. Network-exploitable Heap Overflow & OOB Write in RTP stream parsing. #Patch #Patch #Patch

    Post summary

    The post announces the patching of ten critical RCE vulnerabilities in GStreamer, with CVE‑2026‑3083 and CVE‑2026‑3085 highlighted, noting a CVSS score of 8.8 and referencing heap overflow and OOB write in RTP stream parsing.

    00001293
    7.2K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-3085 - High GStreamer rtpqdm2depay Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStream... https://www.thehackerwire.com/vulnerability/CVE-2026-3085/ https://t.co/63EFkBEq70

    Post summary

    The tweet reports CVE‑2026‑3085, describing a heap‑based buffer overflow in GStreamer that enables RCE, but it does not provide any PoC, exploit code, active exploitation evidence, patch, or false‑positive claim.

    0000036
    138 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-3085: HIGH] GStreamer rtpqdm2depay vulnerability allows remote attackers to execute arbitrary code. Flaw in X-QDM RTP payload processing results in heap-based buffer overflow.#cve,CVE-2026-3085,#cybersecurity https://cvefind.com/CVE-2026-3085

    Post summary

    A high‑severity heap buffer overflow in GStreamer’s rtpqdm2depay is disclosed, allowing remote attackers to execute arbitrary code. No mitigation or exploit details are given.

    0000039
    601 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-3085 GStreamer rtpqdm2depay Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected … https://www.cve.org/CVERecord?id=CVE-2026-3085

    Post summary

    The post announces CVE-2026-3085 as a Heap-based Buffer Overflow in GStreamer’s rtpqdm2depay component that permits remote code execution, but it does not provide a PoC, exploit code, patch, or evidence of real‑world exploitation.

    00000137
    56.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgstreamergstreamer---

Explore more