CVE & CISA-KEV Catalog

CVE-2026-73433

MEDIUM
6.6
CVSS v3
NVD

Description

A flaw was found in GStreamer gst-plugins-good (avidemux). When parsing FUJIFILM metadata in an AVI strd chunk, gst_avi_demux_parse_strd() decrements a remaining-length counter by fixed offsets (98 and 10 bytes) without verifying sufficient data remains. For crafted strd payloads of exactly 106 or 107 bytes, the counter underflows to a very large unsigned value, causing subsequent null-terminated string scanning to read far beyond the allocated heap buffer. Date-format normalization may also write beyond the buffer end. Confirmed impacts include heap out-of-bounds read, out-of-bounds write, heap information disclosure (adjacent data appearing in parsed metadata), and application crash/denial of service. The avidemux element is auto-plugged by playbin, decodebin, and gst-discoverer, so opening or previewing a crafted AVI is sufficient to trigger the issue. Fixed upstream in gst-plugins-good 1.28.6 (GStreamer-SA-2026-0072).

How to fix

Remediation Available
gst-plugins-good1.0Debian
Fixed in:1.28.6-1CVE-2026-73433
gstreamer1-plugins-goodRed Hat / RHEL
Fixed in:0:1.26.7-2.el10_2.5RHSA-2026:55434
Fixed in:0:1.26.7-2.el10_2.5RHSA-2026:55434
Fixed in:0:1.26.7-2.el10_2.5RHSA-2026:55434
Fixed in:0:1.26.7-2.el10_2.5RHSA-2026:55434
Fixed in:0:1.26.7-2.el10_2.5RHSA-2026:55434
Fixed in:0:1.16.1-7.el8_10.3RHSA-2026:56966
Fixed in:0:1.16.1-7.el8_10.3RHSA-2026:56966
Fixed in:0:1.16.1-7.el8_10.3RHSA-2026:56966
gstreamer1-plugins-goodRocky
Fixed in:0:1.26.7-2.el10_2.5RHSA-2026:55434
Fixed in:0:1.26.7-2.el10_2.5RHSA-2026:55434
Fixed in:0:1.26.7-2.el10_2.5RHSA-2026:55434
Fixed in:0:1.26.7-2.el10_2.5RHSA-2026:55434
Fixed in:0:1.26.7-2.el10_2.5RHSA-2026:55434
Fixed in:0:1.16.1-7.el8_10.3RHSA-2026:56966
Fixed in:0:1.16.1-7.el8_10.3RHSA-2026:56966
Fixed in:0:1.16.1-7.el8_10.3RHSA-2026:56966
gstreamer1-plugins-good-debuginfoRocky
Fixed in:0:1.26.7-2.el10_2.5RHSA-2026:55434
Fixed in:0:1.26.7-2.el10_2.5RHSA-2026:55434
Fixed in:0:1.26.7-2.el10_2.5RHSA-2026:55434
Fixed in:0:1.26.7-2.el10_2.5RHSA-2026:55434
Fixed in:0:1.16.1-7.el8_10.3RHSA-2026:56966
Fixed in:0:1.16.1-7.el8_10.3RHSA-2026:56966
Fixed in:0:1.16.1-7.el8_10.3RHSA-2026:56966
Fixed in:0:1.16.1-7.el8_10.3RHSA-2026:56966
gstreamer1-plugins-good-debuginfoRed Hat / RHEL
Fixed in:0:1.26.7-2.el10_2.5RHSA-2026:55434
Fixed in:0:1.26.7-2.el10_2.5RHSA-2026:55434
Fixed in:0:1.26.7-2.el10_2.5RHSA-2026:55434
Fixed in:0:1.26.7-2.el10_2.5RHSA-2026:55434
Fixed in:0:1.16.1-7.el8_10.3RHSA-2026:56966
Fixed in:0:1.16.1-7.el8_10.3RHSA-2026:56966
Fixed in:0:1.16.1-7.el8_10.3RHSA-2026:56966
Fixed in:0:1.16.1-7.el8_10.3RHSA-2026:56966
gstreamer1-plugins-good-debugsourceRed Hat / RHEL
Fixed in:0:1.26.7-2.el10_2.5RHSA-2026:55434
Fixed in:0:1.26.7-2.el10_2.5RHSA-2026:55434
Fixed in:0:1.26.7-2.el10_2.5RHSA-2026:55434
Fixed in:0:1.26.7-2.el10_2.5RHSA-2026:55434
Fixed in:0:1.16.1-7.el8_10.3RHSA-2026:56966
Fixed in:0:1.16.1-7.el8_10.3RHSA-2026:56966
Fixed in:0:1.16.1-7.el8_10.3RHSA-2026:56966
Fixed in:0:1.16.1-7.el8_10.3RHSA-2026:56966
gstreamer1-plugins-good-debugsourceRocky
Fixed in:0:1.26.7-2.el10_2.5RHSA-2026:55434
Fixed in:0:1.26.7-2.el10_2.5RHSA-2026:55434
Fixed in:0:1.26.7-2.el10_2.5RHSA-2026:55434
Fixed in:0:1.26.7-2.el10_2.5RHSA-2026:55434
Fixed in:0:1.16.1-7.el8_10.3RHSA-2026:56966
Fixed in:0:1.16.1-7.el8_10.3RHSA-2026:56966
Fixed in:0:1.16.1-7.el8_10.3RHSA-2026:56966
Fixed in:0:1.16.1-7.el8_10.3RHSA-2026:56966
gstreamer1-plugins-good-gtkRed Hat / RHEL
Fixed in:0:1.26.7-2.el10_2.5RHSA-2026:55434
Fixed in:0:1.26.7-2.el10_2.5RHSA-2026:55434
Fixed in:0:1.26.7-2.el10_2.5RHSA-2026:55434
Fixed in:0:1.26.7-2.el10_2.5RHSA-2026:55434
Fixed in:0:1.16.1-7.el8_10.3RHSA-2026:56966
Fixed in:0:1.16.1-7.el8_10.3RHSA-2026:56966
Fixed in:0:1.16.1-7.el8_10.3RHSA-2026:56966
Fixed in:0:1.16.1-7.el8_10.3RHSA-2026:56966
gstreamer1-plugins-good-gtkRocky
Fixed in:0:1.26.7-2.el10_2.5RHSA-2026:55434
Fixed in:0:1.26.7-2.el10_2.5RHSA-2026:55434
Fixed in:0:1.26.7-2.el10_2.5RHSA-2026:55434
Fixed in:0:1.26.7-2.el10_2.5RHSA-2026:55434
Fixed in:0:1.16.1-7.el8_10.3RHSA-2026:56966
Fixed in:0:1.16.1-7.el8_10.3RHSA-2026:56966
Fixed in:0:1.16.1-7.el8_10.3RHSA-2026:56966
Fixed in:0:1.16.1-7.el8_10.3RHSA-2026:56966
gstreamer1-plugins-good-gtk-debuginfoRocky
Fixed in:0:1.26.7-2.el10_2.5RHSA-2026:55434
Fixed in:0:1.26.7-2.el10_2.5RHSA-2026:55434
Fixed in:0:1.26.7-2.el10_2.5RHSA-2026:55434
Fixed in:0:1.26.7-2.el10_2.5RHSA-2026:55434
Fixed in:0:1.16.1-7.el8_10.3RHSA-2026:56966
Fixed in:0:1.16.1-7.el8_10.3RHSA-2026:56966
Fixed in:0:1.16.1-7.el8_10.3RHSA-2026:56966
Fixed in:0:1.16.1-7.el8_10.3RHSA-2026:56966
gstreamer1-plugins-good-gtk-debuginfoRed Hat / RHEL
Fixed in:0:1.26.7-2.el10_2.5RHSA-2026:55434
Fixed in:0:1.26.7-2.el10_2.5RHSA-2026:55434
Fixed in:0:1.26.7-2.el10_2.5RHSA-2026:55434
Fixed in:0:1.26.7-2.el10_2.5RHSA-2026:55434
Fixed in:0:1.16.1-7.el8_10.3RHSA-2026:56966
Fixed in:0:1.16.1-7.el8_10.3RHSA-2026:56966
Fixed in:0:1.16.1-7.el8_10.3RHSA-2026:56966
Fixed in:0:1.16.1-7.el8_10.3RHSA-2026:56966
gstreamer1-plugins-good-qt-debuginfoRocky
Fixed in:0:1.22.12-7.el9_8.4RHSA-2026:55436
Fixed in:0:1.22.12-7.el9_8.4RHSA-2026:55436
Fixed in:0:1.22.12-7.el9_8.4RHSA-2026:55436
Fixed in:0:1.22.12-7.el9_8.4RHSA-2026:55436
Fixed in:0:1.22.12-7.el9_8.4RHSA-2026:55436
gstreamer1-plugins-good-qt-debuginfoRed Hat / RHEL
Fixed in:0:1.22.12-7.el9_8.4RHSA-2026:55436
Fixed in:0:1.22.12-7.el9_8.4RHSA-2026:55436
Fixed in:0:1.22.12-7.el9_8.4RHSA-2026:55436
Fixed in:0:1.22.12-7.el9_8.4RHSA-2026:55436
Fixed in:0:1.22.12-7.el9_8.4RHSA-2026:55436
gstreamer1-plugins-good-qt6-debuginfoRocky
Fixed in:0:1.26.7-2.el10_2.5RHSA-2026:55434
Fixed in:0:1.26.7-2.el10_2.5RHSA-2026:55434
Fixed in:0:1.26.7-2.el10_2.5RHSA-2026:55434
Fixed in:0:1.26.7-2.el10_2.5RHSA-2026:55434
gstreamer1-plugins-good-qt6-debuginfoRed Hat / RHEL
Fixed in:0:1.26.7-2.el10_2.5RHSA-2026:55434
Fixed in:0:1.26.7-2.el10_2.5RHSA-2026:55434
Fixed in:0:1.26.7-2.el10_2.5RHSA-2026:55434
Fixed in:0:1.26.7-2.el10_2.5RHSA-2026:55434

This vulnerability affects an unusually large number of packages. The highest-confidence fixes are shown above; the full list is longer. Check the referenced advisories for complete coverage.

TridentStack Control can deploy fixes like this automatically across your Windows, macOS, and Linux fleet. See how it works

Remediation is compiled from vendor and distribution security advisories. Always confirm against the linked source for your exact version and platform.

CVSS v3 Vector

Exploitability

Attack VectorLocal
Attack ComplexityLow
Privileges RequiredNone
User InteractionRequired
ScopeUnchanged

Impact

ConfidentialityLow
IntegrityLow
AvailabilityHigh

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H

Exploit Intelligence

0.13%probability of exploitation in 30 days
3rdpercentile

Low risk: more likely to be exploited than 3% of all known CVEs.

References

Related Vulnerabilities

Other CWE-191 vulnerabilities, ordered by exploit likelihood. View all

CVESeverityCVSSEPSSExploitedFix
CVE-2014-0497Critical9.8100%KEVFix
CVE-2020-36221High7.584%-Fix
CVE-2020-36228High7.583%-Fix
CVE-2023-31102High7.871%-Fix
CVE-2024-38063Critical9.871%-Fix
CVE-2017-14496High7.566%-Fix

Common questions

How do I fix CVE-2026-73433?

Published advisories record a fix for 15 affected products. The "How to fix" section on this page lists the fixed version and source advisory for each one, so apply the entry matching what you actually run.

Is CVE-2026-73433 being actively exploited?

Not that we know of. CVE-2026-73433 is not in the CISA Known Exploited Vulnerabilities catalog. Its EPSS score of 0.13% is the estimated probability that it will be exploited in the next 30 days. That is higher than 3% of all scored CVEs.

How severe is CVE-2026-73433?

CVE-2026-73433 has a CVSS v3 base score of 6.6, rated medium. CVSS rates the technical impact if the vulnerability is exploited, not how likely that is, so weigh it alongside the exploit-prediction score when you decide what to patch first.

What does CVE-2026-73433 affect?

Published advisories record a fix for gst-plugins-good1.0 (Debian), gstreamer1-plugins-good (Red Hat / RHEL), gstreamer1-plugins-good (Rocky), gstreamer1-plugins-good-debuginfo (Rocky), and 11 more. Only products with a sourced advisory are listed, so treat this as what we can cite rather than a complete inventory.

Embed a live status badge for CVE-2026-73433
CVE-2026-73433 severity badge

Markdown

[![CVE-2026-73433](https://tridentstack.com/cve/badge/CVE-2026-73433.svg)](https://tridentstack.com/cve/CVE-2026-73433)

HTML

<a href="https://tridentstack.com/cve/CVE-2026-73433"><img src="https://tridentstack.com/cve/badge/CVE-2026-73433.svg" alt="CVE-2026-73433"></a>

Find and fix vulnerabilities across your fleet

TridentStack Control continuously scans your Windows, macOS, and Linux fleet for known vulnerabilities, prioritizes them by severity and active exploitation, and patches them automatically.

See how it worksStart freeThis CVE lookup is free and always will be.

This product uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog. Data as of 2026-08-19.