Security News

Cybersecurity news aggregator

🔄
MEDIUM Updates Red Hat Errata

RHSA-2026:36834: Important: gstreamer1-plugins-bad-free security update

  • What: Security update for GStreamer plugins with vulnerability fixes
  • Impact: Red Hat Enterprise Linux 9 users need to apply the update to address potential security issues
Read Full Article →

Red Hat Product Errata RHSA-2026:36834 - Security Advisory Issued: 2026-07-08 Updated: 2026-07-08 RHSA-2026:36834 - Security Advisory Overview Updated Packages Synopsis Important: gstreamer1-plugins-bad-free security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for gstreamer1-plugins-bad-free is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description GStreamer is a streaming media framework based on graphs of filters which operate on media data. The gstreamer1-plugins-bad-free package contains a collection of plug-ins for GStreamer. Security Fix(es): gstreamer1-plugins-bad-free: GStreamer: Denial of service via AV1 tile_list_obu parser byte/bit confusion (CVE-2026-52718) gstreamer1-plugins-bad-free: GStreamer: Out-of-bounds read via JPEG segment length validation in VA decoder (CVE-2026-52719) gstreamer1-plugins-bad-free: GStreamer: Heap buffer overflow via crafted VNC server rectangle in librfb (CVE-2026-52720) gstreamer1-plugins-bad-free: GStreamer: Signed integer overflow in VMnc decoder cursor payload handling (CVE-2026-52722) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 9 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 x86_64 Red Hat Enterprise Linux for IBM z Systems 9 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.8 s390x Red Hat Enterprise Linux for Power, little endian 9 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.8 ppc64le Red Hat Enterprise Linux for ARM 64 9 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.8 aarch64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.8 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.8 x86_64 Red Hat CodeReady Linux Builder for x86_64 9 x86_64 Red Hat CodeReady Linux Builder for Power, little endian 9 ppc64le Red Hat CodeReady Linux Builder for ARM 64 9 aarch64 Red Hat CodeReady Linux Builder for IBM z Systems 9 s390x Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 9.8 x86_64 Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 9.8 ppc64le Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 9.8 s390x Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 9.8 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.8 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.8 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.8 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.8 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.8 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.8 s390x Fixes BZ - 2486328 - CVE-2026-52718 gstreamer1-plugins-bad-free: GStreamer: Denial of service via AV1 tile_list_obu parser byte/bit confusion BZ - 2486353 - CVE-2026-52719 gstreamer1-plugins-bad-free: GStreamer: Out-of-bounds read via JPEG segment length validation in VA decoder BZ - 2486731 - CVE-2026-52720 gstreamer1-plugins-bad-free: GStreamer: Heap buffer overflow via crafted VNC server rectangle in librfb BZ - 2486733 - CVE-2026-52722 gstreamer1-plugins-bad-free: GStreamer: Signed integer overflow in VMnc decoder cursor payload handling CVEs CVE-2026-52718 CVE-2026-52719 CVE-2026-52720 CVE-2026-52722 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 9 SRPM gstreamer1-plugins-bad-free-1.22.12-7.el9_8.1.src.rpm SHA-256: c68d7a95634a36dafc4088909bec62413eda21ffb6b10cbfd6a4bd2becb5d06a x86_64 gstreamer1-plugins-bad-free-1.22.12-7.el9_8.1.i686.rpm SHA-256: 93a50069e8dd34fa928d8d603dd3dfd9896ba5af9d47e271b5b04537be1ad07e gstreamer1-plugins-bad-free-1.22.12-7.el9_8.1.x86_64.rpm SHA-256: 721a0f6762e778bffbdd3a3ada64754fe83dd01aa0694882c8c4dd8e2f652b10 gstreamer1-plugins-bad-free-debuginfo-1.22.12-7.el9_8.1.i686.rpm SHA-256: b85ba5d7769fcab6c600a5d60cd4992381efeb3223c174e51936af90af60070b gstreamer1-plugins-bad-free-debuginfo-1.22.12-7.el9_8.1.x86_64.rpm SHA-256: dff5f2a5b6d2b4ecc533bef5e1417915e22a6bbb5fc6f06a22f8f6db853a6e21 gstreamer1-plugins-bad-free-debugsource-1.22.12-7.el9_8.1.i686.rpm SHA-256: c68a65fb2a60db2efb163f5a8e38adf8ed498316427860d4e16146a42995b8fa gstreamer1-plugins-bad-free-debugsource-1.22.12-7.el9_8.1.x86_64.rpm SHA-256: f8c1b1371cd6ae39df5058fa692f255414c38dd34ca7a462fdeee28d5b6d369e gstreamer1-plugins-bad-free-libs-1.22.12-7.el9_8.1.i686.rpm SHA-256: 1dcf47d842883b1cd50dcd1af6440bfb902893b22d0874527e5c62f5dd63fee5 gstreamer1-plugins-bad-free-libs-1.22.12-7.el9_8.1.x86_64.rpm SHA-256: eedbbb076eda93cb7f574f22354b7d3a4c57e921b33d44961c35c358de413b59 gstreamer1-plugins-bad-free-libs-debuginfo-1.22.12-7.el9_8.1.i686.rpm SHA-256: 3eec1d8d528a86ec4aab7b840d11c55cb25f664924c4854296b8d35125fbc310 gstreamer1-plugins-bad-free-libs-debuginfo-1.22.12-7.el9_8.1.x86_64.rpm SHA-256: cd27182893aeea549456c92d9988ad67cf043b0e3950c402d906bc03c2714738 Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 SRPM gstreamer1-plugins-bad-free-1.22.12-7.el9_8.1.src.rpm SHA-256: c68d7a95634a36dafc4088909bec62413eda21ffb6b10cbfd6a4bd2becb5d06a x86_64 gstreamer1-plugins-bad-free-1.22.12-7.el9_8.1.i686.rpm SHA-256: 93a50069e8dd34fa928d8d603dd3dfd9896ba5af9d47e271b5b04537be1ad07e gstreamer1-plugins-bad-free-1.22.12-7.el9_8.1.x86_64.rpm SHA-256: 721a0f6762e778bffbdd3a3ada64754fe83dd01aa0694882c8c4dd8e2f652b10 gstreamer1-plugins-bad-free-debuginfo-1.22.12-7.el9_8.1.i686.rpm SHA-256: b85ba5d7769fcab6c600a5d60cd4992381efeb3223c174e51936af90af60070b gstreamer1-plugins-bad-free-debuginfo-1.22.12-7.el9_8.1.x86_64.rpm SHA-256: dff5f2a5b6d2b4ecc533bef5e1417915e22a6bbb5fc6f06a22f8f6db853a6e21 gstreamer1-plugins-bad-free-debugsource-1.22.12-7.el9_8.1.i686.rpm SHA-256: c68a65fb2a60db2efb163f5a8e38adf8ed498316427860d4e16146a42995b8fa gstreamer1-plugins-bad-free-debugsource-1.22.12-7.el9_8.1.x86_64.rpm SHA-256: f8c1b1371cd6ae39df5058fa692f255414c38dd34ca7a462fdeee28d5b6d369e gstreamer1-plugins-bad-free-libs-1.22.12-7.el9_8.1.i686.rpm SHA-256: 1dcf47d842883b1cd50dcd1af6440bfb902893b22d0874527e5c62f5dd63fee5 gstreamer1-plugins-bad-free-libs-1.22.12-7.el9_8.1.x86_64.rpm SHA-256: eedbbb076eda93cb7f574f22354b7d3a4c57e921b33d44961c35c358de413b59 gstreamer1-plugins-bad-free-libs-debuginfo-1.22.12-7.el9_8.1.i686.rpm SHA-256: 3eec1d8d528a86ec4aab7b840d11c55cb25f664924c4854296b8d35125fbc310 gstreamer1-plugins-bad-free-libs-debuginfo-1.22.12-7.el9_8.1.x86_64.rpm SHA-256: cd27182893aeea549456c92d9988ad67cf043b0e3950c402d906bc03c2714738 Red Hat Enterprise Linux for IBM z Systems 9 SRPM gstreamer1-plugins-bad-free-1.22.12-7.el9_8.1.src.rpm SHA-256: c68d7a95634a36dafc4088909bec62413eda21ffb6b10cbfd6a4bd2becb5d06a s390x gstreamer1-plugins-bad-free-1.22.12-7.el9_8.1.s390x.rpm SHA-256: 1937b62929b9c5cb38ea4f4a9678c06088518d21d2590f4948d704591d96a378 gstreamer1-plugins-bad-free-debuginfo-1.22.12-7.el9_8.1.s390x.rpm SHA-256: a0d8c38567208881067b73675ee79b4d0d1acb51016e18f4e78e737d4a6f3b64 gstreamer1-plugins-bad-free-debugsource-1.22.12-7.el9_8.1.s390x.rpm SHA-256: 4bd09654ce74f914267d3350b507c9688ed55b1cd783608a55e78125eef568b9 gstreamer1-plugins-bad-free-libs-1.22.12-7.el9_8.1.s390x.rpm SHA-256: 1e8f4b31f250409068b27d94321be656f536b0b1fe7a37c51c6849c2d1acf0ee gstreamer1-plugins-bad-free-libs-debuginfo-1.22.12-7.el9_8.1.s390x.rpm SHA-256: 6edcb2b0013635ecab3bdf6414f7672260be8d6e66c2c357fa3e52a6fcec61fb Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.8 SRPM gstreamer1-plugins-bad-free-1.22.12-7.el9_8.1.src.rpm SHA-256: c68d7a95634a36dafc4088909bec62413eda21ffb6b10cbfd6a4bd2becb5d06a s390x gstreamer1-plugins-bad-free-1.22.12-7.el9_8.1.s390x.rpm SHA-256: 1937b62929b9c5cb38ea4f4a9678c06088518d21d2590f4948d704591d96a378 gstreamer1-plugins-bad-free-debuginfo-1.22.12-7.el9_8.1.s390x.rpm SHA-256: a0d8c38567208881067b73675ee79b4d0d1acb51016e18f4e78e737d4a6f3b64 gstreamer1-plugins-bad-free-debugsource-1.22.12-7.el9_8.1.s390x.rpm SHA-256: 4bd09654ce74f914267d3350b507c9688ed55b1cd783608a55e78125eef568b9 gstreamer1-plugins-bad-free-libs-1.22.12-7.el9_8.1.s390x.rpm SHA-256: 1e8f4b31f250409068b27d94321be656f536b0b1fe7a37c51c6849c2d1acf0ee gstreamer1-plugins-bad-free-libs-debuginfo-1.22.12-7.el9_8.1.s390x.rpm SHA-256: 6edcb2b0013635ecab3bdf6414f7672260be8d6e66c2c357fa3e52a6fcec61fb Red Hat Enterprise Linux for Power, little endian 9 SRPM gstreamer1-plugins-bad-free-1.22.12-7.el9_8.1.src.rpm SHA-256: c68d7a95634a36dafc4088909bec62413eda21ffb6b10cbfd6a4bd2becb5d06a ppc64le gstreamer1-plugins-bad-free-1.22.12-7.el9_8.1.ppc64le.rpm SHA-256: 73feb2137d4366e0d1ab39a3b45d67413bc6bba0108b43aa73f91fc3fa7a49cc gstreamer1-plugins-bad-free-debuginfo-1.22.12-7.el9_8.1.ppc64le.rpm SHA-256: 4a28e4dea72ee56bdf686978826942aa38561e34905cee174faf5a78da70d53c gstreamer1-plugins-bad-free-debugsource-1.22.12-7.el9_8.1.ppc64le.rpm SHA-256: c29331468c56d7d9fb566c115d0f538d5a23ba8ecffadb40a4b68392922cdc83 gstreamer1-plugins-bad-free-libs-1.22.12-7.el9_8.1.ppc64le.rpm SHA-256: 0322ae37a4016e09466a69d69994cfd2da154da8376f7f9216dfee6363092b47 gst

Share this article