Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-37129

Опубликовано: 09 июл. 2026
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2026-37129: gstreamer1-plugins-good security update (IMPORTANT)

[1.22.12-7.1]

  • Rebase rhel-9.8.0 from 1.18.4 to 1.22.12 to resync with rhel-9.7.0/c9s (this branch had regressed to a stale pre-1.22.12 base) Resolves: RHEL-156269, RHEL-156270
  • Fix CVE-2026-53705: integer overflow in wavpack decoder, re-applied on top of the correct 1.22.12 base Resolves: RHEL-184477

[1.22.12-5]

  • Apply patches for CVE-2026-3083, CVE-2026-3085 Resolves: RHEL-156267, RHEL-156266

[1.22.12-4]

  • Apply patches for CVE-2024-47537, CVE-2024-47539, CVE-2024-47540 CVE-2024-47543, CVE-2024-47544, CVE-2024-47545, CVE-2024-47546, CVE-2024-47596, CVE-2024-47597, CVE-2024-47598, CVE-2024-47599, CVE-2024-47601, CVE-2024-47602, CVE-2024-47603, CVE-2024-47606, CVE-2024-47613, CVE-2024-47774, CVE-2024-47775, CVE-2024-47776, CVE-2024-47777, CVE-2024-47778, CVE-2024-47834
  • Resolves: RHEL-70958, RHEL-70971, RHEL-71033, RHEL-71195
  • Resolves: RHEL-71210, RHEL-71202, RHEL-71171, RHEL-71200
  • Resolves: RHEL-71206, RHEL-71173, RHEL-71198, RHEL-71204
  • Resolves: RHEL-71208, RHEL-71031, RHEL-71007, RHEL-71039
  • Resolves: RHEL-71169, RHEL-71192, RHEL-71161, RHEL-71167
  • Resolves: RHEL-71189

[1.22.12-3]

  • Rebuild
  • Resolves: RHEL-38511, RHEL-41157

[1.22.12-2]

  • Rebuild
  • Resolves: RHEL-38511, RHEL-41157

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

gstreamer1-plugins-good

1.22.12-7.el9_8.1

gstreamer1-plugins-good-gtk

1.22.12-7.el9_8.1

Oracle Linux x86_64

gstreamer1-plugins-good

1.22.12-7.el9_8.1

gstreamer1-plugins-good-gtk

1.22.12-7.el9_8.1

Связанные CVE

Связанные уязвимости

CVSS3: 7.6
ubuntu
около 2 месяцев назад

A flaw was found in GStreamer's WavPack audio decoder in gst-plugins-good. When processing a specially crafted WavPack file, an integer overflow in the buffer size calculation (4 * block_samples * channels) in gst_wavpack_dec_handle_frame() causes a very small heap allocation. The WavPack library then writes decoded audio samples far beyond the allocated buffer, resulting in heap memory corruption. This affects both 32-bit and 64-bit systems since the arithmetic is performed in 32-bit integers before promotion to the allocation size type. A remote attacker could use this flaw to crash an application or potentially execute arbitrary code by convincing a user to open a malicious WavPack audio file.

CVSS3: 7.6
redhat
около 2 месяцев назад

A flaw was found in GStreamer's WavPack audio decoder in gst-plugins-good. When processing a specially crafted WavPack file, an integer overflow in the buffer size calculation (4 * block_samples * channels) in gst_wavpack_dec_handle_frame() causes a very small heap allocation. The WavPack library then writes decoded audio samples far beyond the allocated buffer, resulting in heap memory corruption. This affects both 32-bit and 64-bit systems since the arithmetic is performed in 32-bit integers before promotion to the allocation size type. A remote attacker could use this flaw to crash an application or potentially execute arbitrary code by convincing a user to open a malicious WavPack audio file.

CVSS3: 7.6
nvd
около 2 месяцев назад

A flaw was found in GStreamer's WavPack audio decoder in gst-plugins-good. When processing a specially crafted WavPack file, an integer overflow in the buffer size calculation (4 * block_samples * channels) in gst_wavpack_dec_handle_frame() causes a very small heap allocation. The WavPack library then writes decoded audio samples far beyond the allocated buffer, resulting in heap memory corruption. This affects both 32-bit and 64-bit systems since the arithmetic is performed in 32-bit integers before promotion to the allocation size type. A remote attacker could use this flaw to crash an application or potentially execute arbitrary code by convincing a user to open a malicious WavPack audio file.

CVSS3: 7.6
debian
около 2 месяцев назад

A flaw was found in GStreamer's WavPack audio decoder in gst-plugins-g ...

suse-cvrf
26 дней назад

Security update for gstreamer-plugins-good