Red Hat Product Errata RHSA-2026:47032 - Security Advisory Issued: 2026-07-28 Updated: 2026-07-28 RHSA-2026:47032 - Security Advisory Overview Updated Packages Synopsis Important: gstreamer1-plugins-good security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for gstreamer1-plugins-good is now available for Red Hat Enterprise Linux 10.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description GStreamer is a streaming media framework based on graphs of filters which operate on media data. The gstreamer1-plugins-good packages contain a collection of well-supported plug-ins of good quality and under the LGPL license. Security Fix(es): gstreamer1-plugins-good: GStreamer: Heap buffer overflow in WavPack decoder via integer overflow (CVE-2026-53705) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.0 x86_64 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.0 s390x Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.0 ppc64le Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.0 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.0 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.0 s390x Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.0 ppc64le Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.0 x86_64 Fixes BZ - 2487615 - CVE-2026-53705 gstreamer1-plugins-good: GStreamer: Heap buffer overflow in WavPack decoder via integer overflow CVEs CVE-2026-53705 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.0 SRPM gstreamer1-plugins-good-1.24.11-1.el10_0.3.src.rpm SHA-256: 8ebfc19ade50469c9cf43b58041fbdebd1d1c82b889f75fbb39d95382b689cc4 x86_64 gstreamer1-plugins-good-1.24.11-1.el10_0.3.x86_64.rpm SHA-256: 1a3a262ba5c6879c8cadc2b913066dde8744ddbd641507035e2836abe93372f1 gstreamer1-plugins-good-debuginfo-1.24.11-1.el10_0.3.x86_64.rpm SHA-256: 3591286d6564e4afa0bb6705b0e6d78613c56eb62a7f49b484524ec5a2a62109 gstreamer1-plugins-good-debugsource-1.24.11-1.el10_0.3.x86_64.rpm SHA-256: ac2ca8c2419b9b0fc1bafcf41b0d1e4de79a5561a4ab1e84a25cb4b3890dc660 gstreamer1-plugins-good-gtk-1.24.11-1.el10_0.3.x86_64.rpm SHA-256: 5f0727f4cfa7c4f1f2f2fbcbc5e523dcd6403912bac5b254beeb8da1ded3b468 gstreamer1-plugins-good-gtk-debuginfo-1.24.11-1.el10_0.3.x86_64.rpm SHA-256: 7ea9a783398a4332221a8955a4f6586f521366f2d1ae7a06c03a82c1a470c9fd gstreamer1-plugins-good-qt6-debuginfo-1.24.11-1.el10_0.3.x86_64.rpm SHA-256: 7ce5d6ae18e38dfbc4d467a16b8d263ecf122db8832df8f6fe5b5e70fc914fff Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.0 SRPM gstreamer1-plugins-good-1.24.11-1.el10_0.3.src.rpm SHA-256: 8ebfc19ade50469c9cf43b58041fbdebd1d1c82b889f75fbb39d95382b689cc4 s390x gstreamer1-plugins-good-1.24.11-1.el10_0.3.s390x.rpm SHA-256: 0a489194866140ed9d817c1d409e453a0a6191b248446a27dac13337f61b1386 gstreamer1-plugins-good-debuginfo-1.24.11-1.el10_0.3.s390x.rpm SHA-256: 26d0d212b02135ea470016393ca6119c70f477d25afed06f2d03f5d43eea3bf0 gstreamer1-plugins-good-debugsource-1.24.11-1.el10_0.3.s390x.rpm SHA-256: 6c55886a839480b2bb141f8b11db1f3437acdf8051b5efd5d8436b0f92b237af gstreamer1-plugins-good-gtk-1.24.11-1.el10_0.3.s390x.rpm SHA-256: 16d70083f1f55d35afb04980c5ebf1ac4c656a723a36ac76aca6b30a5be88cde gstreamer1-plugins-good-gtk-debuginfo-1.24.11-1.el10_0.3.s390x.rpm SHA-256: 9296c87a36aebdbb5a29b3c05404364a2b4d7ecfbe491c9c15d0732b4e4d928a gstreamer1-plugins-good-qt6-debuginfo-1.24.11-1.el10_0.3.s390x.rpm SHA-256: ffe553d6b4d542141002705c3320385440509f1f8630ef674eb7b570a46399f2 Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.0 SRPM gstreamer1-plugins-good-1.24.11-1.el10_0.3.src.rpm SHA-256: 8ebfc19ade50469c9cf43b58041fbdebd1d1c82b889f75fbb39d95382b689cc4 ppc64le gstreamer1-plugins-good-1.24.11-1.el10_0.3.ppc64le.rpm SHA-256: 7b63d93a352e09006629c8264dc1ecc89d8f7eb15b77eb3b058c1ab124c04e64 gstreamer1-plugins-good-debuginfo-1.24.11-1.el10_0.3.ppc64le.rpm SHA-256: f4074ed97960b729bf7cfd6ad23500bbbcf20b6148dc9fcc7780b3045da2d463 gstreamer1-plugins-good-debugsource-1.24.11-1.el10_0.3.ppc64le.rpm SHA-256: 787aa9c697ab18d9832e42293419342beaa0cd8cc7b33476b3ef77e17e70be53 gstreamer1-plugins-good-gtk-1.24.11-1.el10_0.3.ppc64le.rpm SHA-256: 7c4a1021e1a4e57629d5159f2ca11fb9c2888e29c04c5660e45d7a176011cd54 gstreamer1-plugins-good-gtk-debuginfo-1.24.11-1.el10_0.3.ppc64le.rpm SHA-256: 8449c58de77688bed65ae185b1cecbe67518677e3ba84b010211c9d5c1d48125 gstreamer1-plugins-good-qt6-debuginfo-1.24.11-1.el10_0.3.ppc64le.rpm SHA-256: 34381f599364a7cdf379a8ecbb9c04977de658ba5acd23f84d35f08b0b4fd336 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.0 SRPM gstreamer1-plugins-good-1.24.11-1.el10_0.3.src.rpm SHA-256: 8ebfc19ade50469c9cf43b58041fbdebd1d1c82b889f75fbb39d95382b689cc4 aarch64 gstreamer1-plugins-good-1.24.11-1.el10_0.3.aarch64.rpm SHA-256: 40856d9512274e88a2d92f9a8c6b9bfa2ba4313a599fb3b8ccc3a26d24c781f3 gstreamer1-plugins-good-debuginfo-1.24.11-1.el10_0.3.aarch64.rpm SHA-256: 9b8beb0f4a3cd88c39f3241a63af94c20329c50232b7f035d9903925a81161b0 gstreamer1-plugins-good-debugsource-1.24.11-1.el10_0.3.aarch64.rpm SHA-256: 7f93245037a179a4cade3ce8114d8357a6cf30a8d2ce57fb0d9590a653ed4c69 gstreamer1-plugins-good-gtk-1.24.11-1.el10_0.3.aarch64.rpm SHA-256: 18a4647a5fe6e6ca2048c98c8612a4acaafb49ad708002108fa2b2ee15d0f19f gstreamer1-plugins-good-gtk-debuginfo-1.24.11-1.el10_0.3.aarch64.rpm SHA-256: b42be9db3f402e416e9468edc5ee5a43c97e902a6c522f214a58749deab2b3c5 gstreamer1-plugins-good-qt6-debuginfo-1.24.11-1.el10_0.3.aarch64.rpm SHA-256: b2ffdcdc90b4b3f5d979b60a4314c73f81b22ab954b7539af61203c9d19616a7 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.0 SRPM gstreamer1-plugins-good-1.24.11-1.el10_0.3.src.rpm SHA-256: 8ebfc19ade50469c9cf43b58041fbdebd1d1c82b889f75fbb39d95382b689cc4 aarch64 gstreamer1-plugins-good-1.24.11-1.el10_0.3.aarch64.rpm SHA-256: 40856d9512274e88a2d92f9a8c6b9bfa2ba4313a599fb3b8ccc3a26d24c781f3 gstreamer1-plugins-good-debuginfo-1.24.11-1.el10_0.3.aarch64.rpm SHA-256: 9b8beb0f4a3cd88c39f3241a63af94c20329c50232b7f035d9903925a81161b0 gstreamer1-plugins-good-debugsource-1.24.11-1.el10_0.3.aarch64.rpm SHA-256: 7f93245037a179a4cade3ce8114d8357a6cf30a8d2ce57fb0d9590a653ed4c69 gstreamer1-plugins-good-gtk-1.24.11-1.el10_0.3.aarch64.rpm SHA-256: 18a4647a5fe6e6ca2048c98c8612a4acaafb49ad708002108fa2b2ee15d0f19f gstreamer1-plugins-good-gtk-debuginfo-1.24.11-1.el10_0.3.aarch64.rpm SHA-256: b42be9db3f402e416e9468edc5ee5a43c97e902a6c522f214a58749deab2b3c5 gstreamer1-plugins-good-qt6-debuginfo-1.24.11-1.el10_0.3.aarch64.rpm SHA-256: b2ffdcdc90b4b3f5d979b60a4314c73f81b22ab954b7539af61203c9d19616a7 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.0 SRPM gstreamer1-plugins-good-1.24.11-1.el10_0.3.src.rpm SHA-256: 8ebfc19ade50469c9cf43b58041fbdebd1d1c82b889f75fbb39d95382b689cc4 s390x gstreamer1-plugins-good-1.24.11-1.el10_0.3.s390x.rpm SHA-256: 0a489194866140ed9d817c1d409e453a0a6191b248446a27dac13337f61b1386 gstreamer1-plugins-good-debuginfo-1.24.11-1.el10_0.3.s390x.rpm SHA-256: 26d0d212b02135ea470016393ca6119c70f477d25afed06f2d03f5d43eea3bf0 gstreamer1-plugins-good-debugsource-1.24.11-1.el10_0.3.s390x.rpm SHA-256: 6c55886a839480b2bb141f8b11db1f3437acdf8051b5efd5d8436b0f92b237af gstreamer1-plugins-good-gtk-1.24.11-1.el10_0.3.s390x.rpm SHA-256: 16d70083f1f55d35afb04980c5ebf1ac4c656a723a36ac76aca6b30a5be88cde gstreamer1-plugins-good-gtk-debuginfo-1.24.11-1.el10_0.3.s390x.rpm SHA-256: 9296c87a36aebdbb5a29b3c05404364a2b4d7ecfbe491c9c15d0732b4e4d928a gstreamer1-plugins-good-qt6-debuginfo-1.24.11-1.el10_0.3.s390x.rpm SHA-256: ffe553d6b4d542141002705c3320385440509f1f8630ef674eb7b570a46399f2 Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.0 SRPM gstreamer1-plugins-good-1.24.11-1.el10_0.3.src.rpm SHA-256: 8ebfc19ade50469c9cf43b58041fbdebd1d1c82b889f75fbb39d95382b689cc4 ppc64le gstreamer1-plugins-good-1.24.11-1.el10_0.3.ppc64le.rpm SHA-256: 7b63d93a352e09006629c8264dc1ecc89d8f7eb15b77eb3b058c1ab124c04e64 gstreamer1-plugins-good-debuginfo-1.24.11-1.el10_0.3.ppc64le.rpm SHA-256: f4074ed97960b729bf7cfd6ad23500bbbcf20b6148dc9fcc7780b3045da2d463 gstreamer1-plugins-good-debugsource-1.24.11-1.el10_0.3.ppc64le.rpm SHA-256: 787aa9c697ab18d9832e42293419342beaa0cd8cc7b33476b3ef77e17e70be53 gstreamer1-plugins-good-gtk-1.24.11-1.el10_0.3.ppc64le.rpm SHA-256: 7c4a1021e1a4e57629d5159f2ca11fb9c2888e29c04c5660e45d7a176011cd54 gstreamer1-plugins-good-gtk-debuginfo-1.24.11-1.el10_0.3.ppc64le.rpm SHA-256: 8449c58de77688bed65ae185b1cecbe67518677e3ba84b010211c9d5c1d48125 gstreamer1-plugins-good-qt6-debuginfo-1.24.11-1.el10_0.3.ppc64le.rpm SHA-256: 34381f599364a7cdf379a8ecbb9c04977de658ba5acd23f84d35f08b0b4fd336 Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.0 SRPM gstreamer1-plugins-good-1.24.11-1.el10_0.3.src.rpm SHA-256: 8ebfc19ade50469c9cf43b58041fbdebd1d1c82b889f75fbb39d95382b689cc4 x86_64 gstreamer1-plugins-good-1.24.11-1.el10_0.3.x86_64.rpm SHA-256: 1a3a262ba5c6879c8cadc2b913066dde8744ddbd641507035e2836abe93372f1
A heap buffer overflow in the GStreamer WavPack decoder (CVE-2026-53705), exploitable via integer overflow, allows potential remote code execution. This vulnerability carries a CVSS 3.1 score of 7.6 (High). The Red Hat security update provides patched packages for Red Hat Enterprise Linux 10.0 Extended Update Support, requiring an update to gstreamer1-plugins-good version 1.24.11-1.el10_0.3.