Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4898 articles · 221206 vulns · 37/41 feeds (7d)
← Back to list
7.5
CVE-2026-85150EXPLOITEDPATCHED
red hat · red hat enterprise linux

Gstreamer1-plugins-base: gstreamer: null/invalid-pointer dereference in gst_rtsp_message_parse_auth_credentials() when parsing a crafted digest authorization/www-authenticate header

Description

A NULL pointer dereference flaw was found in GStreamer's RTSP support library. The vulnerability occurs while parsing an Authorization or WWW-Authenticate header that uses Digest authentication. Specially crafted whitespace placement around a parameter's terminator can cause an internal length calculation to underflow, leading to a crash of the process parsing the header. On an RTSP server this can be triggered by a remote, unauthenticated attacker sending a single malformed request when the server has authentication enabled; the same flaw can also be triggered against an RTSP client by a malicious or compromised RTSP server. Successful exploitation results in a denial of service (application crash) and has no confirmed impact on confidentiality or integrity.

Affected Products

VendorProductVersions
red hatred hat enterprise linux—

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
open sourcegstreamercert_advisory90%

References

  • https://access.redhat.com/errata/RHSA-2026:66460(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/errata/RHSA-2026:67145(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/errata/RHSA-2026:69100(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/security/cve/CVE-2026-85150(vdb-entry, x_refsource_REDHAT)
  • https://bugzilla.redhat.com/show_bug.cgi?id=2527936(issue-tracking, x_refsource_REDHAT)
  • https://gitlab.freedesktop.org/gstreamer/gstreamer-security/-/merge_requests/120
  • https://gitlab.freedesktop.org/gstreamer/gstreamer/-/blob/main/subprojects/gst-plugins-base/gst-libs/gst/rtsp/gstrtspmessage.c#L1408

Related News (2 articles)

Tier B
BSI Advisories14d ago
[NEU] [hoch] GStreamer: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB19d ago
CVE-2026-85150 | Red Hat Enterprise Linux 7/8/9/10 RTSP Digest Authentication Parsing null pointer dereference
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.17.5 NONE
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
0:1.26.7-2.el10_2.2
CWECWE-476
PublishedSep 3, 2026
Last enriched19d ago
Tags
remote code executionfile manipulationdenial of servicemultiple vulnerabilities
Trending Score7
Source articles2
Independent2
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-94184EXP
Fetchmail: fetchmail: stack-based buffer overflow in ntlm authentication (fetchmail-sa-2026-01)
Trending: 59
NONECVE-2026-87766EXP
Bubblewrap: bubblewrap: symlink traversal via /oldroot allows writing files outside sandbox during setup
Trending: 55
NONECVE-2026-93676EXP
Xdg-dbus-proxy: xdg-dbus-proxy: filtering for broadcast messages bypasses path/interface/member checks
Trending: 49
NONECVE-2026-93558
Io.netty/netty-codec-http: netty: unbounded per-connection queue growth in websocketserverextensionhandler leads to denial of service
Trending: 41
NONECVE-2026-93562
Io.netty/netty-codec-http: netty: incomplete validation of malformed transfer-encoding allows http request smuggling
Trending: 41

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 3, 2026
Discovered by ZDM
Sep 3, 2026
Actively Exploited
Sep 21, 2026
Exploit Available
Sep 21, 2026
Patch Available
Sep 21, 2026