
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-3085 is a heap-based buffer overflow vulnerability in GStreamer's rtpqdm2depay component, enabling remote attackers to execute arbitrary code by sending specially crafted X-QDM RTP payloads. It was reported to the vendor on February 11, 2026, and publicly disclosed on March 6, 2026, via a coordinated Zero Day Initiative advisory (ZDI-26-167). All GStreamer versions prior to 1.28.1 are affected. The vulnerability carries a CVSS v3.0 base score of 8.8 (High) (ZDI Advisory, Red Hat Bugzilla).
The root cause is classified as CWE-122 (Heap-based Buffer Overflow) and CWE-1284 (Improper Validation of Specified Quantity in Input). The flaw resides in the rtpqdm2depay plugin's processing of X-QDM RTP payloads: the code copies user-supplied data into a heap buffer without first validating the data's length, allowing an attacker to overflow the buffer. Exploitation requires network access and some form of user interaction with the GStreamer library (e.g., opening a malicious media stream), but no authentication or elevated privileges are needed. The fix is available in the upstream GStreamer commit d60a94dee3c0a0942c9981491bf83e0de1900fbf (ZDI Advisory, GStreamer Commit).
Successful exploitation allows a remote, unauthenticated attacker to execute arbitrary code in the context of the process using GStreamer, resulting in high confidentiality, integrity, and availability impact. Because GStreamer is a widely used multimedia framework embedded in desktop environments, media players, browsers, and embedded systems, the attack surface is broad. Depending on the privileges of the affected process, exploitation could lead to full system compromise, data exfiltration, or serve as a foothold for lateral movement (ZDI Advisory, Red Hat Bugzilla).
No confirmed in-the-wild exploitation or functional public exploit code has been observed as of the time of reporting; the ZDI advisory page describes the vulnerability but does not include exploit code or reproduction steps (ZDI Advisory). The vulnerability was discovered anonymously and submitted through the Zero Day Initiative program. The EPSS score is approximately 0.274%, indicating a low but non-negligible probability of exploitation in the near term. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection plugins are available from Qualys and Tenable Nessus (Red Hat Bugzilla).
rtpqdm2depay plugin to copy more data than the allocated heap buffer can hold./bin/bash, sh), network utilities (curl, wget, nc), or scripting interpreters.gst-launch, media player logs) indicating heap corruption or segmentation faults in rtpqdm2depay-related stack frames./tmp, user home directories), particularly executables or scripts created post-exploitation.The primary remediation is to upgrade GStreamer to version 1.28.1 or later, which includes the upstream fix (GStreamer Commit). Red Hat has issued patches across multiple RHEL versions: RHSA-2026:6259 (RHEL 10), RHSA-2026:6300 (RHEL 9), RHSA-2026:6750 (RHEL 8), RHSA-2026:7673/7850 (RHEL 7 ELS), and additional EUS/SAP errata (Red Hat Bugzilla). Amazon Linux 2 users should apply ALAS2-2026-3209. As a workaround where patching is not immediately possible, restrict RTP traffic to trusted sources via network segmentation or firewall rules, and avoid processing X-QDM RTP streams from untrusted origins.
The vulnerability was reported through the Zero Day Initiative by an anonymous researcher and received standard coordinated disclosure treatment. Red Hat tracked it via Bugzilla (Bug 2447495) and issued numerous errata across RHEL 7 through 10. The Yocto Project security mailing list also discussed the CVE in the context of embedded Linux distributions. No notable independent researcher commentary or significant social media discussion has been identified beyond standard vulnerability aggregator coverage.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."