CVE-2021-3497: Debian Linux

High severity, CVSS 7.8. EPSS: 1.2% chance of exploitation in the next 30 days.

GStreamer before 1.18.4 might access already-freed memory in error code paths when demuxing certain malformed Matroska files.

Affected products

  • Debian Debian Linux: version 9.0 only; version 10.0 only
  • Gstreamer Gstreamer: from 0.10.0, before 1.18.4 (fixed in 1.18.4)
  • Red Hat Enterprise Linux: version 7.0 only; version 8.0 only

Published 2021-04-19. Last modified 2026-06-17.