Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
CVE-2021-3522
See a problem?
Please try reporting it
to the source
first.
Source
https://nvd.nist.gov/vuln/detail/CVE-2021-3522
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-3522.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2021-3522
Downstream
DEBIAN-CVE-2021-3522
DLA-2641-1
DSA-4903-1
OESA-2021-1237
OESA-2022-1601
SUSE-SU-2022:3907-1
SUSE-SU-2022:3911-1
SUSE-SU-2022:3916-1
SUSE-SU-2023:3801-1
UBUNTU-CVE-2021-3522
USN-4959-1
Related
MGASA-2021-0334
SUSE-SU-2022:3907-1
SUSE-SU-2022:3911-1
SUSE-SU-2022:3916-1
SUSE-SU-2023:3801-1
Published
2021-06-02T15:15:07Z
Modified
2025-09-19T13:04:15.780295Z
Severity
5.5 (Medium)
CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS Calculator
Summary
[none]
Details
GStreamer before 1.18.4 may perform an out-of-bounds read when handling certain ID3v2 tags.
References
https://bugzilla.redhat.com/show_bug.cgi?id=1954761
https://security.gentoo.org/glsa/202208-31
https://security.netapp.com/advisory/ntap-20211022-0004/
https://www.oracle.com/security-alerts/cpuoct2021.html
https://security.alpinelinux.org/vuln/CVE-2021-3522
Affected packages
Alpine:v3.18
gst-plugins-base
Package
Name
gst-plugins-base
Purl
pkg:apk/alpine/gst-plugins-base?arch=source
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1.18.4-r0
Affected versions
1.*
1.0.0-r0
1.0.1-r0
1.0.2-r0
1.0.3-r0
1.0.4-r0
1.0.5-r0
1.0.6-r0
1.0.7-r0
1.0.8-r0
1.0.9-r0
1.0.10-r0
1.2.0-r0
1.2.1-r0
1.2.2-r0
1.2.3-r0
1.2.4-r0
1.4.0-r0
1.4.1-r0
1.4.2-r0
1.4.3-r0
1.4.4-r0
1.5.2-r0
1.6.1-r0
1.6.3-r0
1.8.0-r0
1.8.1-r0
1.8.1-r1
1.8.1-r2
1.10.4-r0
1.10.4-r1
1.12.0-r0
1.12.1-r0
1.12.1-r1
1.12.1-r2
1.12.3-r0
1.12.3-r1
1.14.0-r0
1.14.0-r1
1.14.1-r0
1.14.2-r0
1.14.4-r0
1.16.0-r0
1.16.1-r0
1.16.2-r0
1.16.2-r1
1.16.2-r2
1.16.2-r3
1.18.1-r0
1.18.2-r0
1.18.3-r0
Alpine:v3.19
gst-plugins-base
Package
Name
gst-plugins-base
Purl
pkg:apk/alpine/gst-plugins-base?arch=source
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1.18.4-r0
Affected versions
1.*
1.0.0-r0
1.0.1-r0
1.0.2-r0
1.0.3-r0
1.0.4-r0
1.0.5-r0
1.0.6-r0
1.0.7-r0
1.0.8-r0
1.0.9-r0
1.0.10-r0
1.2.0-r0
1.2.1-r0
1.2.2-r0
1.2.3-r0
1.2.4-r0
1.4.0-r0
1.4.1-r0
1.4.2-r0
1.4.3-r0
1.4.4-r0
1.5.2-r0
1.6.1-r0
1.6.3-r0
1.8.0-r0
1.8.1-r0
1.8.1-r1
1.8.1-r2
1.10.4-r0
1.10.4-r1
1.12.0-r0
1.12.1-r0
1.12.1-r1
1.12.1-r2
1.12.3-r0
1.12.3-r1
1.14.0-r0
1.14.0-r1
1.14.1-r0
1.14.2-r0
1.14.4-r0
1.16.0-r0
1.16.1-r0
1.16.2-r0
1.16.2-r1
1.16.2-r2
1.16.2-r3
1.18.1-r0
1.18.2-r0
1.18.3-r0
Alpine:v3.20
gst-plugins-base
Package
Name
gst-plugins-base
Purl
pkg:apk/alpine/gst-plugins-base?arch=source
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1.18.4-r0
Affected versions
1.*
1.0.0-r0
1.0.1-r0
1.0.2-r0
1.0.3-r0
1.0.4-r0
1.0.5-r0
1.0.6-r0
1.0.7-r0
1.0.8-r0
1.0.9-r0
1.0.10-r0
1.2.0-r0
1.2.1-r0
1.2.2-r0
1.2.3-r0
1.2.4-r0
1.4.0-r0
1.4.1-r0
1.4.2-r0
1.4.3-r0
1.4.4-r0
1.5.2-r0
1.6.1-r0
1.6.3-r0
1.8.0-r0
1.8.1-r0
1.8.1-r1
1.8.1-r2
1.10.4-r0
1.10.4-r1
1.12.0-r0
1.12.1-r0
1.12.1-r1
1.12.1-r2
1.12.3-r0
1.12.3-r1
1.14.0-r0
1.14.0-r1
1.14.1-r0
1.14.2-r0
1.14.4-r0
1.16.0-r0
1.16.1-r0
1.16.2-r0
1.16.2-r1
1.16.2-r2
1.16.2-r3
1.18.1-r0
1.18.2-r0
1.18.3-r0
Alpine:v3.21
gst-plugins-base
Package
Name
gst-plugins-base
Purl
pkg:apk/alpine/gst-plugins-base?arch=source
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1.18.4-r0
Affected versions
1.*
1.0.0-r0
1.0.1-r0
1.0.2-r0
1.0.3-r0
1.0.4-r0
1.0.5-r0
1.0.6-r0
1.0.7-r0
1.0.8-r0
1.0.9-r0
1.0.10-r0
1.2.0-r0
1.2.1-r0
1.2.2-r0
1.2.3-r0
1.2.4-r0
1.4.0-r0
1.4.1-r0
1.4.2-r0
1.4.3-r0
1.4.4-r0
1.5.2-r0
1.6.1-r0
1.6.3-r0
1.8.0-r0
1.8.1-r0
1.8.1-r1
1.8.1-r2
1.10.4-r0
1.10.4-r1
1.12.0-r0
1.12.1-r0
1.12.1-r1
1.12.1-r2
1.12.3-r0
1.12.3-r1
1.14.0-r0
1.14.0-r1
1.14.1-r0
1.14.2-r0
1.14.4-r0
1.16.0-r0
1.16.1-r0
1.16.2-r0
1.16.2-r1
1.16.2-r2
1.16.2-r3
1.18.1-r0
1.18.2-r0
1.18.3-r0
Alpine:v3.22
gst-plugins-base
Package
Name
gst-plugins-base
Purl
pkg:apk/alpine/gst-plugins-base?arch=source
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1.18.4-r0
Affected versions
1.*
1.0.0-r0
1.0.1-r0
1.0.2-r0
1.0.3-r0
1.0.4-r0
1.0.5-r0
1.0.6-r0
1.0.7-r0
1.0.8-r0
1.0.9-r0
1.0.10-r0
1.2.0-r0
1.2.1-r0
1.2.2-r0
1.2.3-r0
1.2.4-r0
1.4.0-r0
1.4.1-r0
1.4.2-r0
1.4.3-r0
1.4.4-r0
1.5.2-r0
1.6.1-r0
1.6.3-r0
1.8.0-r0
1.8.1-r0
1.8.1-r1
1.8.1-r2
1.10.4-r0
1.10.4-r1
1.12.0-r0
1.12.1-r0
1.12.1-r1
1.12.1-r2
1.12.3-r0
1.12.3-r1
1.14.0-r0
1.14.0-r1
1.14.1-r0
1.14.2-r0
1.14.4-r0
1.16.0-r0
1.16.1-r0
1.16.2-r0
1.16.2-r1
1.16.2-r2
1.16.2-r3
1.18.1-r0
1.18.2-r0
1.18.3-r0
Git
github.com/gstreamer/gstreamer
Affected ranges
Type
GIT
Repo
https://github.com/gstreamer/gstreamer
Events
Introduced
0
Unknown introduced commit / All previous commits are affected
Fixed
b5b2e3b9208f1f93bc5b0244d29dfed157d78293
CVE-2021-3522 - OSV