CVE-2026-59692
Severity CVSS v4.0:
Pending analysis
Type:
CWE-121
Stack-based Buffer Overflow
Publication date:
09/07/2026
Last modified:
03/08/2026
Description
A stack buffer overflow vulnerability was found in GStreamer's DTLS plugin. During a DTLS handshake, the peer certificate Subject Distinguished Name is printed into a fixed-size 2048-byte stack buffer without bounds checking. A remote unauthenticated attacker can send a certificate with an oversized Subject DN that exceeds the buffer, causing a stack buffer overflow and process crash, resulting in denial of service.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
References to Advisories, Solutions, and Tools
- https://access.redhat.com/errata/RHSA-2026:47179
- https://access.redhat.com/errata/RHSA-2026:47180
- https://access.redhat.com/errata/RHSA-2026:47731
- https://access.redhat.com/security/cve/CVE-2026-59692
- https://bugzilla.redhat.com/show_bug.cgi?id=2497344
- https://gitlab.freedesktop.org/gstreamer/gstreamer-security/-/merge_requests/99
- https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5172



