Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-36749

Опубликовано: 16 июл. 2026
Источник: oracle-oval
Платформа: Oracle Linux 10

Описание

ELSA-2026-36749: gstreamer1-plugins-bad-free security update (IMPORTANT)

[1.26.7-2.4]

  • Fix bytes/bits confusion in AV1 tile data size parsing (CVE-2026-52718) Resolves: RHEL-184391

[1.26.7-2.3]

  • Fix for CVE-2026-52719 Resolves: RHEL-184406

[1.26.7-2.2]

  • Fix integer overflows in VMnc decoder (CVE-2026-52722) Resolves: RHEL-184425

[1.26.7-2.1]

  • Fix for CVE-2026-52720: validate framebuffer update rectangles in VNC source plugin's RFB decoder Resolves: RHEL-184462

Обновленные пакеты

Oracle Linux 10

Oracle Linux aarch64

gstreamer1-plugins-bad-free

1.26.7-2.el10_2.4

gstreamer1-plugins-bad-free-devel

1.26.7-2.el10_2.4

gstreamer1-plugins-bad-free-libs

1.26.7-2.el10_2.4

Oracle Linux x86_64

gstreamer1-plugins-bad-free

1.26.7-2.el10_2.4

gstreamer1-plugins-bad-free-devel

1.26.7-2.el10_2.4

gstreamer1-plugins-bad-free-libs

1.26.7-2.el10_2.4

Связанные уязвимости

rocky
21 день назад

Important: gstreamer1-plugins-bad-free security update

rocky
21 день назад

Important: gstreamer1-plugins-bad-free security update

oracle-oval
24 дня назад

ELSA-2026-36834: gstreamer1-plugins-bad-free security update (IMPORTANT)

CVSS3: 6.5
ubuntu
около 2 месяцев назад

A denial of service vulnerability was found in GStreamer's AV1 codec parser in gst-plugins-bad. The gst_av1_parser_parse_tile_list_obu() function passes a byte count to a bit-reader API that expects a bit count, causing parser desynchronization. A remote attacker could trick a user into opening a specially crafted AV1 media file, triggering an assertion abort and causing the application to crash.

CVSS3: 6.5
redhat
около 2 месяцев назад

A denial of service vulnerability was found in GStreamer's AV1 codec parser in gst-plugins-bad. The gst_av1_parser_parse_tile_list_obu() function passes a byte count to a bit-reader API that expects a bit count, causing parser desynchronization. A remote attacker could trick a user into opening a specially crafted AV1 media file, triggering an assertion abort and causing the application to crash.