CVE-2025-47219

Published: August 9, 2025Last modified: January 22, 2026

Description

In GStreamer through 1.26.1, the isomp4 plugin's qtdemux_parse_trak function may read past the end of a heap buffer while parsing an MP4 file, possibly leading to information disclosure.

Severity score breakdown

ParameterValue
Base score8.1
Attack VectorNETWORK
Attack complexityHIGH
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityHIGH
Integrity impactHIGH
Availability impactHIGH
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Status

ProductReleasePackageStatus
Liberica JDK8jdk-fullFixed (8u482+10)
jre-fullFixed (8u482+10)
11jdk-fullFixed (11.0.30+9)
jre-fullFixed (11.0.30+9)
17jdk-fullFixed (17.0.18+10)
jre-fullFixed (17.0.18+10)
21jdk-fullFixed (21.0.10+10)
jre-fullFixed (21.0.10+10)
25jdk-fullFixed (25.0.2+12)
jre-fullFixed (25.0.2+12)

References

Published BELL-SAs

ON THIS PAGE