Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:55435

Опубликовано: 17 авг. 2026
Источник: rocky
Оценка: Important

Описание

Important: gstreamer1-plugins-ugly-free security update

GStreamer is a streaming media framework, based on graphs of elements which operate on media data. This package contains plug-ins whose license is not fully compatible with LGPL.

Security Fix(es):

  • gstreamer: gstreamer1-plugins-ugly-free: gstreamer: integer overflow/underflow in asfdemux bounds checks leading to out-of-bounds read (CVE-2026-19389)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 10

НаименованиеАрхитектураРелизRPM
gstreamer1-plugins-ugly-freeaarch642.el10_2.2gstreamer1-plugins-ugly-free-1.26.7-2.el10_2.2.aarch64.rpm
gstreamer1-plugins-ugly-freex86_642.el10_2.2gstreamer1-plugins-ugly-free-1.26.7-2.el10_2.2.x86_64.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 7.1
ubuntu
около 2 месяцев назад

Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdemux) when parsing header objects from crafted ASF, WMV, or WMA files. Insufficient validation of attacker-controlled length and size values can bypass bounds checks and cause out-of-bounds heap reads. This can result in application crash, denial of service, or limited information disclosure when untrusted media is processed.

CVSS3: 7.1
redhat
около 2 месяцев назад

Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdemux) when parsing header objects from crafted ASF, WMV, or WMA files. Insufficient validation of attacker-controlled length and size values can bypass bounds checks and cause out-of-bounds heap reads. This can result in application crash, denial of service, or limited information disclosure when untrusted media is processed.

CVSS3: 7.1
nvd
около 2 месяцев назад

Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdemux) when parsing header objects from crafted ASF, WMV, or WMA files. Insufficient validation of attacker-controlled length and size values can bypass bounds checks and cause out-of-bounds heap reads. This can result in application crash, denial of service, or limited information disclosure when untrusted media is processed.

CVSS3: 7.1
debian
около 2 месяцев назад

Multiple integer overflow and underflow vulnerabilities were found in ...

CVSS3: 7.1
redos
3 дня назад

Уязвимость gstreamer1-plugins-ugly-free