Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-53451

Опубликовано: 11 авг. 2026
Источник: oracle-oval
Платформа: Oracle Linux 10

Описание

ELSA-2026-53451: gstreamer1-plugins-good security update (MODERATE)

[1.26.7-2.3]

  • Fix excessive memory allocation from malicious RTP fragmentation unit packets in rtph264depay/rtph265depay (CVE-2026-18649) Resolves: RHEL-224158

Обновленные пакеты

Oracle Linux 10

Oracle Linux aarch64

gstreamer1-plugins-good

1.26.7-2.el10_2.3

gstreamer1-plugins-good-gtk

1.26.7-2.el10_2.3

Oracle Linux x86_64

gstreamer1-plugins-good

1.26.7-2.el10_2.3

gstreamer1-plugins-good-gtk

1.26.7-2.el10_2.3

Связанные CVE

Связанные уязвимости

CVSS3: 7.5
ubuntu
11 дней назад

A flaw was found in the GStreamer gst-plugins-good package. The rtph264depay and rtph265depay RTP depayloader elements do not enforce a maximum size limit on the reassembly buffer used during fragmented RTP packet processing. A remote, unauthenticated attacker can send a continuous stream of RTP fragments without ever transmitting an end-of-fragment marker, causing the reassembly buffer to grow without bound until process memory is exhausted. This results in a denial of service through process termination.

CVSS3: 7.5
redhat
11 дней назад

A flaw was found in the GStreamer gst-plugins-good package. The rtph264depay and rtph265depay RTP depayloader elements do not enforce a maximum size limit on the reassembly buffer used during fragmented RTP packet processing. A remote, unauthenticated attacker can send a continuous stream of RTP fragments without ever transmitting an end-of-fragment marker, causing the reassembly buffer to grow without bound until process memory is exhausted. This results in a denial of service through process termination.

CVSS3: 7.5
nvd
11 дней назад

A flaw was found in the GStreamer gst-plugins-good package. The rtph264depay and rtph265depay RTP depayloader elements do not enforce a maximum size limit on the reassembly buffer used during fragmented RTP packet processing. A remote, unauthenticated attacker can send a continuous stream of RTP fragments without ever transmitting an end-of-fragment marker, causing the reassembly buffer to grow without bound until process memory is exhausted. This results in a denial of service through process termination.

CVSS3: 7.5
debian
11 дней назад

A flaw was found in the GStreamer gst-plugins-good package. The rtph26 ...

rocky
5 дней назад

Moderate: gstreamer1-plugins-good security update