TheZDIBugs@TheZDIBugsDisclosure
A newly identified GStreamer rtpqdm2depay heap-based buffer overflow Remote Code Execution vulnerability (CVE-2026-3085) with CVSS 8.8 has been disclosed on the ZeroDay Initiative site.
CCB Alert@CCBalertPatch
The post announces the patching of ten critical RCE vulnerabilities in GStreamer, with CVE‑2026‑3083 and CVE‑2026‑3085 highlighted, noting a CVSS score of 8.8 and referencing heap overflow and OOB write in RTP stream parsing.
The Hacker Wire@TheHackerWireDisclosure
The tweet reports CVE‑2026‑3085, describing a heap‑based buffer overflow in GStreamer that enables RCE, but it does not provide any PoC, exploit code, active exploitation evidence, patch, or false‑positive claim.
CVEFind.com@CveFindComDisclosure
A high‑severity heap buffer overflow in GStreamer’s rtpqdm2depay is disclosed, allowing remote attackers to execute arbitrary code. No mitigation or exploit details are given.
CVE@CVEnewGeneral
The post announces CVE-2026-3085 as a Heap-based Buffer Overflow in GStreamer’s rtpqdm2depay component that permits remote code execution, but it does not provide a PoC, exploit code, patch, or evidence of real‑world exploitation.