CVE-2026-19387 is a high-severity vulnerability in GStreamer, a widely deployed open-source multimedia framework used across Linux servers, workstations, media applications, and content-processing pipelines. The issue becomes relevant when an affected application processes a specially crafted WAV audio file containing IMA/DVI ADPCM audio data. For your organization, that can turn a seemingly ordinary uploaded, emailed, downloaded, or ingested audio file into a service-disruption or security risk.
You should prioritize this issue if you operate Linux-based systems that accept untrusted media, including customer upload portals, media conversion services, digital-asset workflows, video-conferencing infrastructure, kiosks, or endpoints that play externally sourced audio. The vulnerability can cause application crashes and may create a path to memory corruption or code execution. This post explains the business impact, helps you determine whether you may be affected, and provides technical detection and remediation guidance for security and IT teams.
CVE-2026-19387 was published by the National Vulnerability Database on August 10, 2026. It affects the adpcmdec component in GStreamer’s gst-plugins-bad package, specifically while decoding IMA/DVI ADPCM audio in multi-channel WAV files. Red Hat is the CVE Numbering Authority for the record and credits security researcher Seonwook Kim with reporting the issue.
Red Hat assigned a Common Vulnerability Scoring System version 3.1 score of 7.6 out of 10, categorized as High severity. In plain language, the flaw occurs because the software does not adequately verify audio sample-count values before writing decoded data into memory. A maliciously formed audio file can cause the application to write beyond the memory space allocated for it.
The resulting impact can range from instability and crashes to memory corruption and possible unauthorized code execution. GStreamer upstream addressed the issue in the 1.28.6 release stream, while Linux vendors are issuing or tracking distribution-specific updates. As of the current advisories, fixed package versions differ by operating system and supported release.
Your exposure depends less on whether GStreamer exists somewhere in your environment and more on whether affected applications process media from outside your trust boundary. If customers, partners, employees, or automated feeds can introduce WAV files into a workflow, the vulnerable decoder may be activated without a traditional network intrusion.
Operationally, a successful attack could crash a media player, transcoding worker, upload-processing service, or desktop application. In a high-volume workflow, repeated crashes can delay content publication, interrupt customer-facing services, consume IT response time, and create backlogs in media-processing queues.
The security consequences may be more serious where a media-processing application runs with broad permissions or has access to sensitive data, cloud credentials, shared storage, or production systems. Memory corruption can sometimes enable an attacker to interfere with application behavior or execute unauthorized code, although practical exploitation depends on the environment and defenses in place.
You should also consider governance obligations. Organizations subject to privacy, contractual, or sector-specific security requirements may need to document exposure assessment, patch decisions, compensating controls, and monitoring actions. A preventable interruption involving customer content can affect trust, service commitments, and incident-response costs across the United States and Canada.
A regional bank: You use Linux-based workstations and media tools to prepare customer education videos, record training materials, or process uploaded evidence and audio documents. A malicious WAV file sent through email or an external collaboration channel could crash a vulnerable application, interrupting normal workflows and requiring investigation. If the affected workstation has access to internal systems or sensitive files, the incident scope could expand beyond a single application.
A mid-sized healthcare provider: You operate a patient portal or communications platform that accepts audio attachments, recordings, or multimedia messages. A crafted file could disrupt the service that scans, previews, or converts incoming media. The operational impact may include delayed communications, recovery work, and additional scrutiny of whether protected health information was exposed.
An e-commerce marketplace: You use automated content-processing workers to normalize seller-generated product videos and audio before publication. An attacker could submit a malicious file designed to cause worker crashes, reducing throughput or disrupting listings. If the workers run with unnecessary access to other systems, a contained processing flaw could become a broader environment risk.
A Canadian public-sector agency: You accept multimedia files through public forms, records requests, or public-engagement platforms. A successful denial-of-service attempt against media-processing infrastructure could slow service delivery and force staff to handle submissions manually. Strong file isolation and timely vendor patches reduce the chance that externally supplied content affects core systems.
gst-plugins-bad1.0, gstreamer1-plugins-bad-free, or related multimedia dependencies on Linux systems.gst-plugins-bad1.0 version 1.22.0-4+deb12u7, which Debian currently lists as vulnerable.CVE-2026-19387 is a practical reminder that file-processing workflows can become an entry point into critical business systems. IntegSec can help you identify exposed media-processing paths, validate patch coverage, test containment controls, and prioritize remediation based on actual business risk. A focused penetration test can reveal where untrusted content reaches sensitive workloads and whether your defenses limit the impact of exploitation. Contact IntegSec to strengthen your security posture with evidence-driven testing and meaningful risk reduction.
CVE-2026-19387 is a heap out-of-bounds write, classified as CWE-787, in GStreamer’s adpcmdec element within the gst-plugins-bad component. The vulnerable logic decodes IMA/DVI ADPCM audio carried in multi-channel WAV files. It insufficiently validates the per-block sample count before writing decoded samples to the allocated output buffer. A crafted file can therefore cause writes beyond the intended heap allocation.
The attack vector is network-based in the CVSS assessment because an attacker can deliver a malicious file through a remote workflow, such as an upload service, shared file location, email-delivered attachment, or content pipeline. The attack complexity is low, no prior privileges are required, and user interaction is required because a vulnerable application must process the attacker-controlled file. Red Hat’s vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H, producing a 7.6 High score.
The NVD record remains marked as awaiting enrichment, but it references upstream GStreamer remediation work and multiple Red Hat errata.
Version verification should begin with package inventory and then move to application-level dependency validation. Package names and installed versions vary by distribution, so teams should check both operating-system repositories and container images.
adpcmdec, media-preview services, or transcoding workers shortly after WAV-file ingestion.