Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:53452

Опубликовано: 12 авг. 2026
Источник: rocky
Оценка: Moderate

Описание

Moderate: gstreamer1-plugins-good security update

GStreamer is a streaming media framework based on graphs of filters which operate on media data. The gstreamer1-plugins-good packages contain a collection of well-supported plug-ins of good quality and under the LGPL license.

Security Fix(es):

  • gst-plugins-good: gst-plugins-good: unbounded memory growth in rtph264depay and rtph265depay RTP depayloaders (CVE-2026-18649)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 9

НаименованиеАрхитектураРелизRPM
gstreamer1-plugins-goodaarch647.el9_8.2gstreamer1-plugins-good-1.22.12-7.el9_8.2.aarch64.rpm
gstreamer1-plugins-good-gtkaarch647.el9_8.2gstreamer1-plugins-good-gtk-1.22.12-7.el9_8.2.aarch64.rpm
gstreamer1-plugins-goodi6867.el9_8.2gstreamer1-plugins-good-1.22.12-7.el9_8.2.i686.rpm
gstreamer1-plugins-goodx86_647.el9_8.2gstreamer1-plugins-good-1.22.12-7.el9_8.2.x86_64.rpm
gstreamer1-plugins-good-gtki6867.el9_8.2gstreamer1-plugins-good-gtk-1.22.12-7.el9_8.2.i686.rpm
gstreamer1-plugins-good-gtkx86_647.el9_8.2gstreamer1-plugins-good-gtk-1.22.12-7.el9_8.2.x86_64.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 7.5
ubuntu
11 дней назад

A flaw was found in the GStreamer gst-plugins-good package. The rtph264depay and rtph265depay RTP depayloader elements do not enforce a maximum size limit on the reassembly buffer used during fragmented RTP packet processing. A remote, unauthenticated attacker can send a continuous stream of RTP fragments without ever transmitting an end-of-fragment marker, causing the reassembly buffer to grow without bound until process memory is exhausted. This results in a denial of service through process termination.

CVSS3: 7.5
redhat
11 дней назад

A flaw was found in the GStreamer gst-plugins-good package. The rtph264depay and rtph265depay RTP depayloader elements do not enforce a maximum size limit on the reassembly buffer used during fragmented RTP packet processing. A remote, unauthenticated attacker can send a continuous stream of RTP fragments without ever transmitting an end-of-fragment marker, causing the reassembly buffer to grow without bound until process memory is exhausted. This results in a denial of service through process termination.

CVSS3: 7.5
nvd
11 дней назад

A flaw was found in the GStreamer gst-plugins-good package. The rtph264depay and rtph265depay RTP depayloader elements do not enforce a maximum size limit on the reassembly buffer used during fragmented RTP packet processing. A remote, unauthenticated attacker can send a continuous stream of RTP fragments without ever transmitting an end-of-fragment marker, causing the reassembly buffer to grow without bound until process memory is exhausted. This results in a denial of service through process termination.

CVSS3: 7.5
debian
11 дней назад

A flaw was found in the GStreamer gst-plugins-good package. The rtph26 ...

rocky
5 дней назад

Moderate: gstreamer1-plugins-good security update