CVE-2025-47183

Publication date 7 August 2025

Last updated 28 August 2025


Ubuntu priority

Cvss 3 Severity Score

6.6 · Medium

Score breakdown

Description

In GStreamer through 1.26.1, the isomp4 plugin's qtdemux_parse_tree function may read past the end of a heap buffer while parsing an MP4 file, leading to information disclosure.

Status

Package Ubuntu Release Status
gst-plugins-good1.0 25.10 questing
Fixed 1.26.2-1ubuntu1
25.04 plucky
Fixed 1.26.0-1ubuntu2.1
24.04 LTS noble
Fixed 1.24.2-1ubuntu1.2
22.04 LTS jammy
Fixed 1.20.3-0ubuntu1.4
20.04 LTS focal Ignored changes too intrusive
18.04 LTS bionic Ignored changes too intrusive
16.04 LTS xenial Ignored changes too intrusive

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
gst-plugins-good1.0

Severity score breakdown

Parameter Value
Base score 6.6 · Medium
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction Required
Scope Unchanged
Confidentiality High
Integrity impact None
Availability impact High
Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H