Описание
ELSA-2026-55865: gstreamer1-plugins-bad-free and gstreamer1-plugins-ugly-free security update (IMPORTANT)
gstreamer1-plugins-bad-free [1.22.12-7.4]
- Fix ADPCM decoder negotiation and input size check (CVE-2026-19387) Resolves: RHEL-235496
gstreamer1-plugins-ugly-free [1.22.12-6.2]
- Fix integer overflows during bounds checks in asfdemux
- Resolves: RHEL-235519
Обновленные пакеты
Oracle Linux 9
Oracle Linux aarch64
gstreamer1-plugins-bad-free
1.22.12-7.el9_8.4
gstreamer1-plugins-bad-free-devel
1.22.12-7.el9_8.4
gstreamer1-plugins-bad-free-libs
1.22.12-7.el9_8.4
gstreamer1-plugins-ugly-free
1.22.12-6.el9_8.2
Oracle Linux x86_64
gstreamer1-plugins-bad-free
1.22.12-7.el9_8.4
gstreamer1-plugins-bad-free-devel
1.22.12-7.el9_8.4
gstreamer1-plugins-bad-free-libs
1.22.12-7.el9_8.4
gstreamer1-plugins-ugly-free
1.22.12-6.el9_8.2
Связанные CVE
Связанные уязвимости
Important: gstreamer1-plugins-bad-free and gstreamer1-plugins-ugly-free security update
Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdemux) when parsing header objects from crafted ASF, WMV, or WMA files. Insufficient validation of attacker-controlled length and size values can bypass bounds checks and cause out-of-bounds heap reads. This can result in application crash, denial of service, or limited information disclosure when untrusted media is processed.
Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdemux) when parsing header objects from crafted ASF, WMV, or WMA files. Insufficient validation of attacker-controlled length and size values can bypass bounds checks and cause out-of-bounds heap reads. This can result in application crash, denial of service, or limited information disclosure when untrusted media is processed.
Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdemux) when parsing header objects from crafted ASF, WMV, or WMA files. Insufficient validation of attacker-controlled length and size values can bypass bounds checks and cause out-of-bounds heap reads. This can result in application crash, denial of service, or limited information disclosure when untrusted media is processed.
Multiple integer overflow and underflow vulnerabilities were found in ...