Red Hat Product Errata RHSA-2026:47180 - Security Advisory Issued: 2026-07-28 Updated: 2026-07-28 RHSA-2026:47180 - Security Advisory Overview Updated Packages Synopsis Important: gstreamer1-plugins-bad-free security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for gstreamer1-plugins-bad-free is now available for Red Hat Enterprise Linux 10. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description GStreamer is a streaming media framework based on graphs of filters which operate on media data. The gstreamer1-plugins-bad-free package contains a collection of plug-ins for GStreamer. Security Fix(es): gstreamer: gstreamer: rfbsrc/librfb Hextile heap out-of-bounds write with 16bpp framebuffer (CVE-2026-59691) gstreamer: gstreamer: DTLS certificate Subject DN stack buffer overflow in openssl_verify_callback (CVE-2026-59692) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 10 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 x86_64 Red Hat Enterprise Linux for IBM z Systems 10 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 s390x Red Hat Enterprise Linux for Power, little endian 10 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2 ppc64le Red Hat Enterprise Linux for ARM 64 10 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.2 aarch64 Red Hat CodeReady Linux Builder for x86_64 10 x86_64 Red Hat CodeReady Linux Builder for Power, little endian 10 ppc64le Red Hat CodeReady Linux Builder for ARM 64 10 aarch64 Red Hat CodeReady Linux Builder for IBM z Systems 10 s390x Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 10.2 x86_64 Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 10.2 ppc64le Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 10.2 s390x Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 10.2 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.2 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.2 s390x Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.2 ppc64le Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.2 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 10.2 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 10.2 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 10.2 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 10.2 s390x Fixes BZ - 2497343 - CVE-2026-59691 gstreamer: gstreamer: rfbsrc/librfb Hextile heap out-of-bounds write with 16bpp framebuffer BZ - 2497344 - CVE-2026-59692 gstreamer: gstreamer: DTLS certificate Subject DN stack buffer overflow in openssl_verify_callback CVEs CVE-2026-59691 CVE-2026-59692 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 10 SRPM gstreamer1-plugins-bad-free-1.26.7-2.el10_2.6.src.rpm SHA-256: cf0e6c86e989efbc7a90b462726d66ea4500d12cdb163d8563ed0a4eddae72f1 x86_64 gstreamer1-plugins-bad-free-1.26.7-2.el10_2.6.x86_64.rpm SHA-256: 2df036c30da555644bde357f5fe3ac9f02aa3be220606e9c184335a198f9590c gstreamer1-plugins-bad-free-debuginfo-1.26.7-2.el10_2.6.x86_64.rpm SHA-256: 9b7b470ccf07fe0a6007022afe72f74c235d42a43954b0ab2f03d7258a860ec8 gstreamer1-plugins-bad-free-debugsource-1.26.7-2.el10_2.6.x86_64.rpm SHA-256: b329cf88d66d29b608cb39ca43472d1a9b1ebb5d565ad8302a8989cac5dbb026 gstreamer1-plugins-bad-free-libs-1.26.7-2.el10_2.6.x86_64.rpm SHA-256: fc49d4e339d80bd3c14ba4419e16327a05a17de1f263ae32225bbbdc4bcf59ba gstreamer1-plugins-bad-free-libs-debuginfo-1.26.7-2.el10_2.6.x86_64.rpm SHA-256: 3da611d2e1497992af047e104dcd3113312266751ab335bac54c372c2387f8c3 Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 SRPM gstreamer1-plugins-bad-free-1.26.7-2.el10_2.6.src.rpm SHA-256: cf0e6c86e989efbc7a90b462726d66ea4500d12cdb163d8563ed0a4eddae72f1 x86_64 gstreamer1-plugins-bad-free-1.26.7-2.el10_2.6.x86_64.rpm SHA-256: 2df036c30da555644bde357f5fe3ac9f02aa3be220606e9c184335a198f9590c gstreamer1-plugins-bad-free-debuginfo-1.26.7-2.el10_2.6.x86_64.rpm SHA-256: 9b7b470ccf07fe0a6007022afe72f74c235d42a43954b0ab2f03d7258a860ec8 gstreamer1-plugins-bad-free-debugsource-1.26.7-2.el10_2.6.x86_64.rpm SHA-256: b329cf88d66d29b608cb39ca43472d1a9b1ebb5d565ad8302a8989cac5dbb026 gstreamer1-plugins-bad-free-libs-1.26.7-2.el10_2.6.x86_64.rpm SHA-256: fc49d4e339d80bd3c14ba4419e16327a05a17de1f263ae32225bbbdc4bcf59ba gstreamer1-plugins-bad-free-libs-debuginfo-1.26.7-2.el10_2.6.x86_64.rpm SHA-256: 3da611d2e1497992af047e104dcd3113312266751ab335bac54c372c2387f8c3 Red Hat Enterprise Linux for IBM z Systems 10 SRPM gstreamer1-plugins-bad-free-1.26.7-2.el10_2.6.src.rpm SHA-256: cf0e6c86e989efbc7a90b462726d66ea4500d12cdb163d8563ed0a4eddae72f1 s390x gstreamer1-plugins-bad-free-1.26.7-2.el10_2.6.s390x.rpm SHA-256: 2a786dc2c117bba627b3a2edffd891c11735d0a3744ac7ca2ad9dc879cf734b8 gstreamer1-plugins-bad-free-debuginfo-1.26.7-2.el10_2.6.s390x.rpm SHA-256: 92871994e3be5796a983ed95014f85bd8eaed7626dc1830117d3d94e3723766c gstreamer1-plugins-bad-free-debugsource-1.26.7-2.el10_2.6.s390x.rpm SHA-256: 769233bab2adae906ff21c766e0e72a7f5b65fd0cdd72084427ee022e1cbabea gstreamer1-plugins-bad-free-libs-1.26.7-2.el10_2.6.s390x.rpm SHA-256: f6b95b29c878db449eddc603a978bfc1589757a7af961519bf0e9bd3c7982ee6 gstreamer1-plugins-bad-free-libs-debuginfo-1.26.7-2.el10_2.6.s390x.rpm SHA-256: e7e7ff89e31ea8537c694bac4bfa40b6e4cad13dc422eda0b32abe7bf54ab30c Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 SRPM gstreamer1-plugins-bad-free-1.26.7-2.el10_2.6.src.rpm SHA-256: cf0e6c86e989efbc7a90b462726d66ea4500d12cdb163d8563ed0a4eddae72f1 s390x gstreamer1-plugins-bad-free-1.26.7-2.el10_2.6.s390x.rpm SHA-256: 2a786dc2c117bba627b3a2edffd891c11735d0a3744ac7ca2ad9dc879cf734b8 gstreamer1-plugins-bad-free-debuginfo-1.26.7-2.el10_2.6.s390x.rpm SHA-256: 92871994e3be5796a983ed95014f85bd8eaed7626dc1830117d3d94e3723766c gstreamer1-plugins-bad-free-debugsource-1.26.7-2.el10_2.6.s390x.rpm SHA-256: 769233bab2adae906ff21c766e0e72a7f5b65fd0cdd72084427ee022e1cbabea gstreamer1-plugins-bad-free-libs-1.26.7-2.el10_2.6.s390x.rpm SHA-256: f6b95b29c878db449eddc603a978bfc1589757a7af961519bf0e9bd3c7982ee6 gstreamer1-plugins-bad-free-libs-debuginfo-1.26.7-2.el10_2.6.s390x.rpm SHA-256: e7e7ff89e31ea8537c694bac4bfa40b6e4cad13dc422eda0b32abe7bf54ab30c Red Hat Enterprise Linux for Power, little endian 10 SRPM gstreamer1-plugins-bad-free-1.26.7-2.el10_2.6.src.rpm SHA-256: cf0e6c86e989efbc7a90b462726d66ea4500d12cdb163d8563ed0a4eddae72f1 ppc64le gstreamer1-plugins-bad-free-1.26.7-2.el10_2.6.ppc64le.rpm SHA-256: 307341b53b679c8ce5cd85d3f3ff82ac0edcb946df2f9fa3989f6a8c68e97eed gstreamer1-plugins-bad-free-debuginfo-1.26.7-2.el10_2.6.ppc64le.rpm SHA-256: 1786495e08fdabcb776aa05964c47b64e4b8ae55d6e2f443957085a91d60e929 gstreamer1-plugins-bad-free-debugsource-1.26.7-2.el10_2.6.ppc64le.rpm SHA-256: abee17e901549bc6d7e6f7ade3f29c0735ab793485cf0dc37a9d66d9ad772b8e gstreamer1-plugins-bad-free-libs-1.26.7-2.el10_2.6.ppc64le.rpm SHA-256: 2cdb8aafc739cb746dff361c7b81c4016ffb274db35378ee594bffe4df1e4c96 gstreamer1-plugins-bad-free-libs-debuginfo-1.26.7-2.el10_2.6.ppc64le.rpm SHA-256: 34282fb349f51025a343f0f3e4ef0f7563a7206517992cebccd5347c11bcc28c Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2 SRPM gstreamer1-plugins-bad-free-1.26.7-2.el10_2.6.src.rpm SHA-256: cf0e6c86e989efbc7a90b462726d66ea4500d12cdb163d8563ed0a4eddae72f1 ppc64le gstreamer1-plugins-bad-free-1.26.7-2.el10_2.6.ppc64le.rpm SHA-256: 307341b53b679c8ce5cd85d3f3ff82ac0edcb946df2f9fa3989f6a8c68e97eed gstreamer1-plugins-bad-free-debuginfo-1.26.7-2.el10_2.6.ppc64le.rpm SHA-256: 1786495e08fdabcb776aa05964c47b64e4b8ae55d6e2f443957085a91d60e929 gstreamer1-plugins-bad-free-debugsource-1.26.7-2.el10_2.6.ppc64le.rpm SHA-256: abee17e901549bc6d7e6f7ade3f29c0735ab793485cf0dc37a9d66d9ad772b8e gstreamer1-plugins-bad-free-libs-1.26.7-2.el10_2.6.ppc64le.rpm SHA-256: 2cdb8aafc739cb746dff361c7b81c4016ffb274db35378ee594bffe4df1e4c96 gstreamer1-plugins-bad-free-libs-debuginfo-1.26.7-2.el10_2.6.ppc64le.rpm SHA-256: 34282fb349f51025a343f0f3e4ef0f7563a7206517992cebccd5347c11bcc28c Red Hat Enterprise Linux for ARM 64 10 SRPM gstreamer1-plugins-bad-free-1.26.7-2.el10_2.6.src.rpm SHA-256: cf0e6c86e989efbc7a90b462726d66ea4500d12cdb163d8563ed0a4eddae72f1 aarch64 gstreamer1-plugins-bad-free-1.26.7-2.el10_2.6.aarch64.rpm SHA-256: bf303e434479252105547e2883d8a78858b42323cd26d14e6d36aa0b1ff0bf6c gstreamer1-plugins-bad-free-debuginfo-1.26.7-2.el10_2.6.aarch64.rpm SHA-256: 2741ce15a9a75a2659853f4fff37ff73360ab751fce1677276f33c713c9115da gstreamer1-plugins-bad-free-debugsource-1.26.7-2.el10_2.6.aarch64.rpm SHA-256: cdce07dc28d10f52f68e616c6f47505b86a9376a30c727c759792bd4ebc1c98f gstreamer1-plugins-bad-free-libs-1.26.7-2.el10_2.6.aarch64.rpm SHA-256: d25b10887c285c5cfff94c8b641e22322e936c86b305dd18f16ec33dfe1e8075 gstreamer1-plugins-bad-free-libs-debuginfo-1.26.7-2.el10_2.6.aarch64.rpm SHA-256: 70b8f8e419154e6d6cd01cb18248e08e48dc1141b8487544806a9a02145798af Red H
This Important security update for gstreamer1-plugins-bad-free addresses two high-severity vulnerabilities: CVE-2026-59691 (CVSS 7.1), a heap out-of-bounds write in the RFB Hextile decoder, and CVE-2026-59692 (CVSS 7.5), a stack buffer overflow in the DTLS certificate verification callback. The advisory applies to Red Hat Enterprise Linux 10 and its Extended Update Support variants. Administrators should apply the update via the referenced Red Hat channels to remediate these issues.