CVE-2022-1925: Debian Linux

High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.

DOS / potential heap overwrite in mkv demuxing using HEADERSTRIP decompression. Integer overflow in matroskaparse element in gst_matroska_decompress_data function which causes a heap overflow. Due to restrictions on chunk sizes in the matroskademux element, the overflow can't be triggered, however the matroskaparse element has no size checks.

Affected products

  • Debian Debian Linux: version 10.0 only; version 11.0 only
  • Gstreamer Gstreamer: before 1.20.3 (fixed in 1.20.3)

Published 2022-07-19. Last modified 2026-06-17.