Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-55865

Опубликовано: 17 авг. 2026
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2026-55865: gstreamer1-plugins-bad-free and gstreamer1-plugins-ugly-free security update (IMPORTANT)

gstreamer1-plugins-bad-free [1.22.12-7.4]

  • Fix ADPCM decoder negotiation and input size check (CVE-2026-19387) Resolves: RHEL-235496

gstreamer1-plugins-ugly-free [1.22.12-6.2]

  • Fix integer overflows during bounds checks in asfdemux
  • Resolves: RHEL-235519

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

gstreamer1-plugins-bad-free

1.22.12-7.el9_8.4

gstreamer1-plugins-bad-free-devel

1.22.12-7.el9_8.4

gstreamer1-plugins-bad-free-libs

1.22.12-7.el9_8.4

gstreamer1-plugins-ugly-free

1.22.12-6.el9_8.2

Oracle Linux x86_64

gstreamer1-plugins-bad-free

1.22.12-7.el9_8.4

gstreamer1-plugins-bad-free-devel

1.22.12-7.el9_8.4

gstreamer1-plugins-bad-free-libs

1.22.12-7.el9_8.4

gstreamer1-plugins-ugly-free

1.22.12-6.el9_8.2

Связанные CVE

Связанные уязвимости

rocky
около 1 месяца назад

Important: gstreamer1-plugins-bad-free and gstreamer1-plugins-ugly-free security update

CVSS3: 7.1
ubuntu
около 2 месяцев назад

Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdemux) when parsing header objects from crafted ASF, WMV, or WMA files. Insufficient validation of attacker-controlled length and size values can bypass bounds checks and cause out-of-bounds heap reads. This can result in application crash, denial of service, or limited information disclosure when untrusted media is processed.

CVSS3: 7.1
redhat
около 2 месяцев назад

Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdemux) when parsing header objects from crafted ASF, WMV, or WMA files. Insufficient validation of attacker-controlled length and size values can bypass bounds checks and cause out-of-bounds heap reads. This can result in application crash, denial of service, or limited information disclosure when untrusted media is processed.

CVSS3: 7.1
nvd
около 2 месяцев назад

Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdemux) when parsing header objects from crafted ASF, WMV, or WMA files. Insufficient validation of attacker-controlled length and size values can bypass bounds checks and cause out-of-bounds heap reads. This can result in application crash, denial of service, or limited information disclosure when untrusted media is processed.

CVSS3: 7.1
debian
около 2 месяцев назад

Multiple integer overflow and underflow vulnerabilities were found in ...