GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference vulnerability has been discovered in the gst_jpeg_dec_negotiate function in gstjpegdec.c. This function does not check for a NULL return value from gst_video_decoder_set_output_state. When this happens, dereferences of the outstate pointer will lead to a null pointer dereference. This vulnerability can result in a Denial of Service (DoS) by triggering a segmentation fault (SEGV). This vulnerability is fixed in 1.24.10.
The product dereferences a pointer that it expects to be valid but is NULL.
| Name | Vendor | Start Version | End Version | 
|---|---|---|---|
| Gstreamer | Gstreamer_project | * | 1.24.10 (excluding) | 
| Red Hat Enterprise Linux 9 | RedHat | gstreamer1-plugins-good-0:1.22.12-4.el9 | * | 
| Gst-plugins-good1.0 | Ubuntu | esm-infra/focal | * | 
| Gst-plugins-good1.0 | Ubuntu | focal | * | 
| Gst-plugins-good1.0 | Ubuntu | jammy | * | 
| Gst-plugins-good1.0 | Ubuntu | noble | * | 
| Gst-plugins-good1.0 | Ubuntu | oracular | * | 
| Gst-plugins-good1.0 | Ubuntu | upstream | * |