Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:36834

Опубликовано: 10 июл. 2026
Источник: rocky
Оценка: Important

Описание

Important: gstreamer1-plugins-bad-free security update

GStreamer is a streaming media framework based on graphs of filters which operate on media data. The gstreamer1-plugins-bad-free package contains a collection of plug-ins for GStreamer.

Security Fix(es):

  • gstreamer1-plugins-bad-free: GStreamer: Denial of service via AV1 tile_list_obu parser byte/bit confusion (CVE-2026-52718)

  • gstreamer1-plugins-bad-free: GStreamer: Out-of-bounds read via JPEG segment length validation in VA decoder (CVE-2026-52719)

  • gstreamer1-plugins-bad-free: GStreamer: Heap buffer overflow via crafted VNC server rectangle in librfb (CVE-2026-52720)

  • gstreamer1-plugins-bad-free: GStreamer: Signed integer overflow in VMnc decoder cursor payload handling (CVE-2026-52722)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 9

НаименованиеАрхитектураРелизRPM
gstreamer1-plugins-bad-freei6867.el9_8.1gstreamer1-plugins-bad-free-1.22.12-7.el9_8.1.i686.rpm
gstreamer1-plugins-bad-freex86_647.el9_8.1gstreamer1-plugins-bad-free-1.22.12-7.el9_8.1.x86_64.rpm
gstreamer1-plugins-bad-free-libsi6867.el9_8.1gstreamer1-plugins-bad-free-libs-1.22.12-7.el9_8.1.i686.rpm
gstreamer1-plugins-bad-free-libsx86_647.el9_8.1gstreamer1-plugins-bad-free-libs-1.22.12-7.el9_8.1.x86_64.rpm

Показывать по

Связанные уязвимости

rocky
21 день назад

Important: gstreamer1-plugins-bad-free security update

oracle-oval
24 дня назад

ELSA-2026-36834: gstreamer1-plugins-bad-free security update (IMPORTANT)

oracle-oval
16 дней назад

ELSA-2026-36749: gstreamer1-plugins-bad-free security update (IMPORTANT)

CVSS3: 6.5
ubuntu
около 2 месяцев назад

A denial of service vulnerability was found in GStreamer's AV1 codec parser in gst-plugins-bad. The gst_av1_parser_parse_tile_list_obu() function passes a byte count to a bit-reader API that expects a bit count, causing parser desynchronization. A remote attacker could trick a user into opening a specially crafted AV1 media file, triggering an assertion abort and causing the application to crash.

CVSS3: 6.5
redhat
около 2 месяцев назад

A denial of service vulnerability was found in GStreamer's AV1 codec parser in gst-plugins-bad. The gst_av1_parser_parse_tile_list_obu() function passes a byte count to a bit-reader API that expects a bit count, causing parser desynchronization. A remote attacker could trick a user into opening a specially crafted AV1 media file, triggering an assertion abort and causing the application to crash.