Description: A heap-based buffer overflow vulnerability was found in GStreamer in the AV1 codec parser when handling certain malformed streams. A malicious third party could use this flaw to trigger a crash in the application and possibly affect code execution through heap manipulation. Broken commit info: Bugfix commit info: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/b76a801f57353b893c344025cac56413140fca6d https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/5634.patch
PR: https://e.gitee.com/openanolis/repos/src-anolis-os/gstreamer1-plugins-bad-free/pulls/18?tab=files