Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-36834

Опубликовано: 08 июл. 2026
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2026-36834: gstreamer1-plugins-bad-free security update (IMPORTANT)

[1.22.12-7.1]

  • Sync with c9s release -5..-7: fix for CVE-2026-2923, CVE-2026-3082 in dvbsuboverlay and jpegparser Resolves: RHEL-156242, RHEL-156255

[1.22.12-4.4]

  • Fix bytes/bits confusion in AV1 tile data size parsing (CVE-2026-52718) Resolves: RHEL-184388

[1.22.12-4.3]

  • Fix for CVE-2026-52719: vajpegdecoder out-of-bounds read Resolves: RHEL-184403

[1.22.12-4.2]

  • Fix integer overflows in vmnc decoder (CVE-2026-52722) Resolves: RHEL-184422

[1.22.12-4.1]

  • Fix for CVE-2026-52720: validate framebuffer update rectangles in librfb plugin Resolves: RHEL-184459

[1.22.12-4]

  • fix for CVE-2025-3887 Resolves: RHEL-93059

[1.22.12-3]

  • Rebuild
  • Resolves: RHEL-38511, RHEL-41157

[1.22.12-2]

  • Rebuild
  • Resolves: RHEL-38511, RHEL-41157

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

gstreamer1-plugins-bad-free

1.22.12-7.el9_8.1

gstreamer1-plugins-bad-free-devel

1.22.12-7.el9_8.1

gstreamer1-plugins-bad-free-libs

1.22.12-7.el9_8.1

Oracle Linux x86_64

gstreamer1-plugins-bad-free

1.22.12-7.el9_8.1

gstreamer1-plugins-bad-free-devel

1.22.12-7.el9_8.1

gstreamer1-plugins-bad-free-libs

1.22.12-7.el9_8.1

Связанные уязвимости

rocky
21 день назад

Important: gstreamer1-plugins-bad-free security update

rocky
21 день назад

Important: gstreamer1-plugins-bad-free security update

oracle-oval
16 дней назад

ELSA-2026-36749: gstreamer1-plugins-bad-free security update (IMPORTANT)

CVSS3: 6.5
ubuntu
около 2 месяцев назад

A denial of service vulnerability was found in GStreamer's AV1 codec parser in gst-plugins-bad. The gst_av1_parser_parse_tile_list_obu() function passes a byte count to a bit-reader API that expects a bit count, causing parser desynchronization. A remote attacker could trick a user into opening a specially crafted AV1 media file, triggering an assertion abort and causing the application to crash.

CVSS3: 6.5
redhat
около 2 месяцев назад

A denial of service vulnerability was found in GStreamer's AV1 codec parser in gst-plugins-bad. The gst_av1_parser_parse_tile_list_obu() function passes a byte count to a bit-reader API that expects a bit count, causing parser desynchronization. A remote attacker could trick a user into opening a specially crafted AV1 media file, triggering an assertion abort and causing the application to crash.