Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-53452

Опубликовано: 11 авг. 2026
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2026-53452: gstreamer1-plugins-good security update (MODERATE)

[1.22.12-7.2]

  • Fix CVE-2026-18649: limit fragmentation unit size in RTP H.264/H.265 depayloaders to prevent excessive memory usage Resolves: RHEL-224162

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

gstreamer1-plugins-good

1.22.12-7.el9_8.2

gstreamer1-plugins-good-gtk

1.22.12-7.el9_8.2

Oracle Linux x86_64

gstreamer1-plugins-good

1.22.12-7.el9_8.2

gstreamer1-plugins-good-gtk

1.22.12-7.el9_8.2

Связанные CVE

Связанные уязвимости

CVSS3: 7.5
ubuntu
11 дней назад

A flaw was found in the GStreamer gst-plugins-good package. The rtph264depay and rtph265depay RTP depayloader elements do not enforce a maximum size limit on the reassembly buffer used during fragmented RTP packet processing. A remote, unauthenticated attacker can send a continuous stream of RTP fragments without ever transmitting an end-of-fragment marker, causing the reassembly buffer to grow without bound until process memory is exhausted. This results in a denial of service through process termination.

CVSS3: 7.5
redhat
11 дней назад

A flaw was found in the GStreamer gst-plugins-good package. The rtph264depay and rtph265depay RTP depayloader elements do not enforce a maximum size limit on the reassembly buffer used during fragmented RTP packet processing. A remote, unauthenticated attacker can send a continuous stream of RTP fragments without ever transmitting an end-of-fragment marker, causing the reassembly buffer to grow without bound until process memory is exhausted. This results in a denial of service through process termination.

CVSS3: 7.5
nvd
11 дней назад

A flaw was found in the GStreamer gst-plugins-good package. The rtph264depay and rtph265depay RTP depayloader elements do not enforce a maximum size limit on the reassembly buffer used during fragmented RTP packet processing. A remote, unauthenticated attacker can send a continuous stream of RTP fragments without ever transmitting an end-of-fragment marker, causing the reassembly buffer to grow without bound until process memory is exhausted. This results in a denial of service through process termination.

CVSS3: 7.5
debian
11 дней назад

A flaw was found in the GStreamer gst-plugins-good package. The rtph26 ...

rocky
5 дней назад

Moderate: gstreamer1-plugins-good security update