CVE-2021-3185
NixOS vulnerability analysis and mitigation

Overview

A critical vulnerability (CVE-2021-3185) was discovered in the gstreamer h264 component of gst-plugins-bad before version 1.18.1. The flaw was identified during a source code audit by Theori and was disclosed on January 20, 2021. The vulnerability affects the H.264 parsing functionality in the gstreamer software, specifically impacting all versions of gstreamer 1.x before 1.18.1 (Openwall).

Technical details

The vulnerability exists in the gst_h264_slice_parse_dec_ref_pic_marking function when parsing H.264 bitstreams. The flaw occurs due to a missing bounds check on the dec_ref_pic_m->n_ref_pic_marking index variable, where the destination array dec_ref_pic_m->ref_pic_marking has a fixed size of 10 elements. The vulnerability has been assigned a CVSS v3.1 base score of 9.8 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H (NVD).

Impact

When exploited, this vulnerability could lead to stack buffer overflow, memory corruption, and potentially remote code execution. The overflown array is within a GstH264DecRefPicMarking structure allocated on the stack, allowing attackers to modify other fields within GstH264SliceHdr without triggering stack canaries. Successful exploitation could result in complete system compromise (Openwall).

Exploitability

The vulnerable code path can be triggered when gstreamer parses any attacker-controlled H.264 content. Researchers at Theori successfully demonstrated remote code execution in an environment with partial ASLR and without stack canaries, though exploitation would be significantly more difficult on modern desktop Linux distributions (Openwall).

Mitigation and workarounds

The vulnerability was fixed in gstreamer versions 1.18.1 and 1.16.3 through a patch that implements proper bounds checking on the array index. Users are advised to upgrade to these or later versions. The fix was implemented through a merge request in the GStreamer project repository (Openwall).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-75874CRITICAL10
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74990CRITICAL9.8
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74989CRITICAL9.8
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74988CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74987CRITICAL9.8
  • NixOS logoNixOS
  • MozillaFirefox-branding-upstream
NoYesAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management