Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:55865

Опубликовано: 18 авг. 2026
Источник: rocky
Оценка: Important

Описание

Important: gstreamer1-plugins-bad-free and gstreamer1-plugins-ugly-free security update

GStreamer is a streaming media framework based on graphs of filters which operate on media data. The gstreamer1-plugins-bad-free package contains a collection of plug-ins for GStreamer.

Security Fix(es):

  • gstreamer: gstreamer1-plugins-bad-free: gstreamer: heap out-of-bounds write in adpcmdec IMA/DVI ADPCM decoder (CVE-2026-19387)

  • gstreamer: gstreamer1-plugins-ugly-free: gstreamer: integer overflow/underflow in asfdemux bounds checks leading to out-of-bounds read (CVE-2026-19389)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 9

НаименованиеАрхитектураРелизRPM
gstreamer1-plugins-bad-freeaarch647.el9_8.4gstreamer1-plugins-bad-free-1.22.12-7.el9_8.4.aarch64.rpm
gstreamer1-plugins-bad-free-libsaarch647.el9_8.4gstreamer1-plugins-bad-free-libs-1.22.12-7.el9_8.4.aarch64.rpm
gstreamer1-plugins-ugly-freeaarch646.el9_8.2gstreamer1-plugins-ugly-free-1.22.12-6.el9_8.2.aarch64.rpm
gstreamer1-plugins-bad-freei6867.el9_8.4gstreamer1-plugins-bad-free-1.22.12-7.el9_8.4.i686.rpm
gstreamer1-plugins-bad-freex86_647.el9_8.4gstreamer1-plugins-bad-free-1.22.12-7.el9_8.4.x86_64.rpm
gstreamer1-plugins-bad-free-libsi6867.el9_8.4gstreamer1-plugins-bad-free-libs-1.22.12-7.el9_8.4.i686.rpm
gstreamer1-plugins-bad-free-libsx86_647.el9_8.4gstreamer1-plugins-bad-free-libs-1.22.12-7.el9_8.4.x86_64.rpm
gstreamer1-plugins-ugly-freei6866.el9_8.2gstreamer1-plugins-ugly-free-1.22.12-6.el9_8.2.i686.rpm
gstreamer1-plugins-ugly-freex86_646.el9_8.2gstreamer1-plugins-ugly-free-1.22.12-6.el9_8.2.x86_64.rpm

Показывать по

Связанные CVE

Связанные уязвимости

oracle-oval
около 1 месяца назад

ELSA-2026-55865: gstreamer1-plugins-bad-free and gstreamer1-plugins-ugly-free security update (IMPORTANT)

CVSS3: 7.1
ubuntu
около 2 месяцев назад

Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdemux) when parsing header objects from crafted ASF, WMV, or WMA files. Insufficient validation of attacker-controlled length and size values can bypass bounds checks and cause out-of-bounds heap reads. This can result in application crash, denial of service, or limited information disclosure when untrusted media is processed.

CVSS3: 7.1
redhat
около 2 месяцев назад

Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdemux) when parsing header objects from crafted ASF, WMV, or WMA files. Insufficient validation of attacker-controlled length and size values can bypass bounds checks and cause out-of-bounds heap reads. This can result in application crash, denial of service, or limited information disclosure when untrusted media is processed.

CVSS3: 7.1
nvd
около 2 месяцев назад

Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdemux) when parsing header objects from crafted ASF, WMV, or WMA files. Insufficient validation of attacker-controlled length and size values can bypass bounds checks and cause out-of-bounds heap reads. This can result in application crash, denial of service, or limited information disclosure when untrusted media is processed.

CVSS3: 7.1
debian
около 2 месяцев назад

Multiple integer overflow and underflow vulnerabilities were found in ...