Red Hat Product Errata RHSA-2026:36749 - Security Advisory Issued: 2026-07-08 Updated: 2026-07-08 RHSA-2026:36749 - Security Advisory Overview Updated Packages Synopsis Important: gstreamer1-plugins-bad-free security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for gstreamer1-plugins-bad-free is now available for Red Hat Enterprise Linux 10. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description GStreamer is a streaming media framework based on graphs of filters which operate on media data. The gstreamer1-plugins-bad-free package contains a collection of plug-ins for GStreamer. Security Fix(es): gstreamer1-plugins-bad-free: GStreamer: Denial of service via AV1 tile_list_obu parser byte/bit confusion (CVE-2026-52718) gstreamer1-plugins-bad-free: GStreamer: Out-of-bounds read via JPEG segment length validation in VA decoder (CVE-2026-52719) gstreamer1-plugins-bad-free: GStreamer: Heap buffer overflow via crafted VNC server rectangle in librfb (CVE-2026-52720) gstreamer1-plugins-bad-free: GStreamer: Signed integer overflow in VMnc decoder cursor payload handling (CVE-2026-52722) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 10 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 x86_64 Red Hat Enterprise Linux for IBM z Systems 10 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 s390x Red Hat Enterprise Linux for Power, little endian 10 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2 ppc64le Red Hat Enterprise Linux for ARM 64 10 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.2 aarch64 Red Hat CodeReady Linux Builder for x86_64 10 x86_64 Red Hat CodeReady Linux Builder for Power, little endian 10 ppc64le Red Hat CodeReady Linux Builder for ARM 64 10 aarch64 Red Hat CodeReady Linux Builder for IBM z Systems 10 s390x Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 10.2 x86_64 Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 10.2 ppc64le Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 10.2 s390x Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 10.2 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.2 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.2 s390x Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.2 ppc64le Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.2 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 10.2 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 10.2 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 10.2 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 10.2 s390x Fixes BZ - 2486328 - CVE-2026-52718 gstreamer1-plugins-bad-free: GStreamer: Denial of service via AV1 tile_list_obu parser byte/bit confusion BZ - 2486353 - CVE-2026-52719 gstreamer1-plugins-bad-free: GStreamer: Out-of-bounds read via JPEG segment length validation in VA decoder BZ - 2486731 - CVE-2026-52720 gstreamer1-plugins-bad-free: GStreamer: Heap buffer overflow via crafted VNC server rectangle in librfb BZ - 2486733 - CVE-2026-52722 gstreamer1-plugins-bad-free: GStreamer: Signed integer overflow in VMnc decoder cursor payload handling CVEs CVE-2026-52718 CVE-2026-52719 CVE-2026-52720 CVE-2026-52722 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 10 SRPM gstreamer1-plugins-bad-free-1.26.7-2.el10_2.4.src.rpm SHA-256: a47c5993b9a2afbddd9aa4fce9a6815dd9fd8ccf60bbf2666a1e0cea261a26ad x86_64 gstreamer1-plugins-bad-free-1.26.7-2.el10_2.4.x86_64.rpm SHA-256: d97c4c93a6b8acac270d2bbbe70487c0db734a92e97831fa64fd53e5b1130e53 gstreamer1-plugins-bad-free-debuginfo-1.26.7-2.el10_2.4.x86_64.rpm SHA-256: 0d198918b4433255e0b32e59a6b2a83b8af330e82158abfeeb97344fd81d4742 gstreamer1-plugins-bad-free-debugsource-1.26.7-2.el10_2.4.x86_64.rpm SHA-256: a4369f9c1b5f9aa842f6bb603525417c0ad5178d6b9e91a8f0c7191fe778e693 gstreamer1-plugins-bad-free-libs-1.26.7-2.el10_2.4.x86_64.rpm SHA-256: 78590b0201217965624a4fd8cb89c2d12c7eba112c11c68b9737fcd83f71b5b8 gstreamer1-plugins-bad-free-libs-debuginfo-1.26.7-2.el10_2.4.x86_64.rpm SHA-256: 4244d798c452b9f273f90b79ff6668e122b959290d5f7c6490974168518f220e Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 SRPM gstreamer1-plugins-bad-free-1.26.7-2.el10_2.4.src.rpm SHA-256: a47c5993b9a2afbddd9aa4fce9a6815dd9fd8ccf60bbf2666a1e0cea261a26ad x86_64 gstreamer1-plugins-bad-free-1.26.7-2.el10_2.4.x86_64.rpm SHA-256: d97c4c93a6b8acac270d2bbbe70487c0db734a92e97831fa64fd53e5b1130e53 gstreamer1-plugins-bad-free-debuginfo-1.26.7-2.el10_2.4.x86_64.rpm SHA-256: 0d198918b4433255e0b32e59a6b2a83b8af330e82158abfeeb97344fd81d4742 gstreamer1-plugins-bad-free-debugsource-1.26.7-2.el10_2.4.x86_64.rpm SHA-256: a4369f9c1b5f9aa842f6bb603525417c0ad5178d6b9e91a8f0c7191fe778e693 gstreamer1-plugins-bad-free-libs-1.26.7-2.el10_2.4.x86_64.rpm SHA-256: 78590b0201217965624a4fd8cb89c2d12c7eba112c11c68b9737fcd83f71b5b8 gstreamer1-plugins-bad-free-libs-debuginfo-1.26.7-2.el10_2.4.x86_64.rpm SHA-256: 4244d798c452b9f273f90b79ff6668e122b959290d5f7c6490974168518f220e Red Hat Enterprise Linux for IBM z Systems 10 SRPM gstreamer1-plugins-bad-free-1.26.7-2.el10_2.4.src.rpm SHA-256: a47c5993b9a2afbddd9aa4fce9a6815dd9fd8ccf60bbf2666a1e0cea261a26ad s390x gstreamer1-plugins-bad-free-1.26.7-2.el10_2.4.s390x.rpm SHA-256: aa5f7ddececa91a87cfaa697a902220833481163d5fa4fc7b0ee7966b343bebd gstreamer1-plugins-bad-free-debuginfo-1.26.7-2.el10_2.4.s390x.rpm SHA-256: 5dc9d903a7dacea16d6c7825a14ed6afb536781e05881354daa20007a5c0f1b1 gstreamer1-plugins-bad-free-debugsource-1.26.7-2.el10_2.4.s390x.rpm SHA-256: 68f108c3414713425c850d2e98e6a768f9551d9845464ed1426d3d803a6c7009 gstreamer1-plugins-bad-free-libs-1.26.7-2.el10_2.4.s390x.rpm SHA-256: 6b5adce2c8a9a198fa10bbcc47d1f9af4f806e3e23132f3c2c9b7b8375897b01 gstreamer1-plugins-bad-free-libs-debuginfo-1.26.7-2.el10_2.4.s390x.rpm SHA-256: 1bd4dcdfe0933a4a98e792a296572b85f555b1e5579f00576bdd1c992da700cb Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 SRPM gstreamer1-plugins-bad-free-1.26.7-2.el10_2.4.src.rpm SHA-256: a47c5993b9a2afbddd9aa4fce9a6815dd9fd8ccf60bbf2666a1e0cea261a26ad s390x gstreamer1-plugins-bad-free-1.26.7-2.el10_2.4.s390x.rpm SHA-256: aa5f7ddececa91a87cfaa697a902220833481163d5fa4fc7b0ee7966b343bebd gstreamer1-plugins-bad-free-debuginfo-1.26.7-2.el10_2.4.s390x.rpm SHA-256: 5dc9d903a7dacea16d6c7825a14ed6afb536781e05881354daa20007a5c0f1b1 gstreamer1-plugins-bad-free-debugsource-1.26.7-2.el10_2.4.s390x.rpm SHA-256: 68f108c3414713425c850d2e98e6a768f9551d9845464ed1426d3d803a6c7009 gstreamer1-plugins-bad-free-libs-1.26.7-2.el10_2.4.s390x.rpm SHA-256: 6b5adce2c8a9a198fa10bbcc47d1f9af4f806e3e23132f3c2c9b7b8375897b01 gstreamer1-plugins-bad-free-libs-debuginfo-1.26.7-2.el10_2.4.s390x.rpm SHA-256: 1bd4dcdfe0933a4a98e792a296572b85f555b1e5579f00576bdd1c992da700cb Red Hat Enterprise Linux for Power, little endian 10 SRPM gstreamer1-plugins-bad-free-1.26.7-2.el10_2.4.src.rpm SHA-256: a47c5993b9a2afbddd9aa4fce9a6815dd9fd8ccf60bbf2666a1e0cea261a26ad ppc64le gstreamer1-plugins-bad-free-1.26.7-2.el10_2.4.ppc64le.rpm SHA-256: 31351ea800cc2a797214610723a200e41167759df876c3e358314115a0a01d39 gstreamer1-plugins-bad-free-debuginfo-1.26.7-2.el10_2.4.ppc64le.rpm SHA-256: 82c3cc2f845b9483b2616555850f2f9682903632fbcf59c64958f0cd162a0ebe gstreamer1-plugins-bad-free-debugsource-1.26.7-2.el10_2.4.ppc64le.rpm SHA-256: 6da7dc36a2d51f1b1e59b66549864c59e72ff2424517e774e27cd4d62ba7e38b gstreamer1-plugins-bad-free-libs-1.26.7-2.el10_2.4.ppc64le.rpm SHA-256: 2cad61685780a82da5866cd2b8307a65422ea5f4fc5fbffa700e859d3922812f gstreamer1-plugins-bad-free-libs-debuginfo-1.26.7-2.el10_2.4.ppc64le.rpm SHA-256: 0281ad69652ace16aaac2bbfc8dbecb46a54808fa91241ae78f8315e13a097ab Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2 SRPM gstreamer1-plugins-bad-free-1.26.7-2.el10_2.4.src.rpm SHA-256: a47c5993b9a2afbddd9aa4fce9a6815dd9fd8ccf60bbf2666a1e0cea261a26ad ppc64le gstreamer1-plugins-bad-free-1.26.7-2.el10_2.4.ppc64le.rpm SHA-256: 31351ea800cc2a797214610723a200e41167759df876c3e358314115a0a01d39 gstreamer1-plugins-bad-free-debuginfo-1.26.7-2.el10_2.4.ppc64le.rpm SHA-256: 82c3cc2f845b9483b2616555850f2f9682903632fbcf59c64958f0cd162a0ebe gstreamer1-plugins-bad-free-debugsource-1.26.7-2.el10_2.4.ppc64le.rpm SHA-256: 6da7dc36a2d51f1b1e59b66549864c59e72ff2424517e774e27cd4d62ba7e38b gstreamer1-plugins-bad-free-libs-1.26.7-2.el10_2.4.ppc64le.rpm SHA-256: 2cad61685780a82da5866cd2b8307a65422ea5f4fc5fbffa700e859d3922812f gstreamer1-plugins-bad-free-libs-debuginfo-1.26.7-2.el10_2.4.ppc64le.rpm SHA-256: 0281ad69652ace16aaac2bbfc8dbecb46a54808fa91241ae78f8315e13a097ab Red Hat Enterprise Linux for ARM 64 10 SRPM gstreamer1-plugins-bad-free-1.26.7-2.el10_2.4.src.rpm SHA-256: a47c5993b9a2afbddd9aa4fce9a6815dd9fd8ccf60bbf2666a1e0cea261a26ad aarch64 gstreamer1-plugins-bad-free-1.26.7-2.el10_2.4.aarch64.rpm SHA-256: c197e3feeb6b4e3e9f23c5c242eee82d62a917e688930110e2d9e2
This Red Hat security advisory addresses four vulnerabilities in the gstreamer1-plugins-bad-free package for RHEL 10, including denial of service, out-of-bounds read, heap buffer overflow, and integer overflow flaws in various media parsers (AV1, JPEG, VNC, VMnc). The CVSS scores for three specified CVEs range from Medium (6.5) to High (8.8). Red Hat has rated this update as Important and released patches; affected systems should be updated using the provided solution link.