CVE-2023-44446
NixOS vulnerability analysis and mitigation

Overview

A use-after-free vulnerability (CVE-2023-44446) was discovered in the MXF demuxer component of GStreamer. The vulnerability affects GStreamer gst-plugins-bad versions prior to 1.22.7, disclosed on November 13, 2023. The flaw exists within the parsing of MXF video files and stems from the lack of validating the existence of an object prior to performing operations on it (GStreamer Advisory, ZDI Advisory).

Technical details

The vulnerability is classified as a use-after-free (read) condition in the MXF demuxer when handling certain files. It has been assigned a CVSS v3.1 base score of 8.8 (HIGH) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H. The vulnerability is tracked as CWE-416 (Use After Free) and requires user interaction to exploit, though it can be triggered remotely (NVD, Red Hat).

Impact

The vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. If successfully exploited, attackers can execute code in the context of the current process. The issue could allow a malicious third party to trigger a crash in the application and potentially achieve code execution (ZDI Advisory).

Exploitability

The vulnerability requires interaction with the GStreamer library to exploit, though attack vectors may vary depending on the implementation. The specific flaw is triggered through the parsing of malicious MXF video files. The vulnerability was initially reported to the vendor on October 19, 2023, and was publicly disclosed on November 15, 2023 (ZDI Advisory).

Mitigation and workarounds

The vulnerability has been fixed in GStreamer gst-plugins-bad version 1.22.7. Users of older branches of GStreamer should apply the available patch and recompile their installations. Various Linux distributions have also released security updates to address this vulnerability (GStreamer Advisory, Red Hat).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-75874CRITICAL10
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74990CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74989CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74988CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74987CRITICAL9.8
  • NixOS logoNixOS
  • MozillaFirefox
NoYesAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management