CVE-2026-46470: Freedesktop Gst-Plugins-Good

Critical severity, CVSS 9.1. EPSS: 0.4% chance of exploitation in the next 30 days.

An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's qtdemux_audio_caps function does not sufficiently validate atom data before performing division operations, leading to denial of service due to integer division by zero.

Affected products

  • Freedesktop Gst-Plugins-Good: before 1.28.2 (fixed in 1.28.2)

Published 2026-05-14. Last modified 2026-06-17.