Security News

Cybersecurity news aggregator

🔄
MEDIUM Updates Red Hat Errata

RHSA-2026:54664: Important: gstreamer1-plugins-bad-free security update

  • What: Security update for gstreamer1-plugins-bad-free
  • Impact: Red Hat Enterprise Linux 8.8 systems may be affected
Read Full Article →

Red Hat Product Errata RHSA-2026:54664 - Security Advisory Issued: 2026-08-13 Updated: 2026-08-13 RHSA-2026:54664 - Security Advisory Overview Updated Packages Synopsis Important: gstreamer1-plugins-bad-free security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for gstreamer1-plugins-bad-free is now available for Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions and Red Hat Enterprise Linux 8.8 Telecommunications Update Service. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description GStreamer is a streaming media framework based on graphs of filters which operate on media data. The gstreamer1-plugins-bad-free package contains a collection of plug-ins for GStreamer. Security Fix(es): gstreamer: gstreamer: rfbsrc/librfb Hextile heap out-of-bounds write with 16bpp framebuffer (CVE-2026-59691) gstreamer: gstreamer: DTLS certificate Subject DN stack buffer overflow in openssl_verify_callback (CVE-2026-59692) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Life Cycle Long Life 8.8 x86_64 Red Hat Enterprise Linux Server - TUS 8.8 x86_64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.8 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.8 x86_64 Fixes BZ - 2497343 - CVE-2026-59691 gstreamer: gstreamer: rfbsrc/librfb Hextile heap out-of-bounds write with 16bpp framebuffer BZ - 2497344 - CVE-2026-59692 gstreamer: gstreamer: DTLS certificate Subject DN stack buffer overflow in openssl_verify_callback CVEs CVE-2026-59691 CVE-2026-59692 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Life Cycle Long Life 8.8 SRPM gstreamer1-plugins-bad-free-1.16.1-4.el8_8.4.src.rpm SHA-256: 97187b55720e07e6dc7819b22afc2a209c2bf904061f2f67385a9069aaa9e61c x86_64 gstreamer1-plugins-bad-free-1.16.1-4.el8_8.4.i686.rpm SHA-256: 4a3df1e5235389a88c3ad17e73e93970d814c32c51e2a85330ea7a795c6a22e1 gstreamer1-plugins-bad-free-1.16.1-4.el8_8.4.x86_64.rpm SHA-256: 8aa1591ffdcae2750fbf18802f2f28dde18a91989d8879bc9c0967719201a8b2 gstreamer1-plugins-bad-free-debuginfo-1.16.1-4.el8_8.4.i686.rpm SHA-256: 3cb2a2cc52b2eb8bcd4620863caa20f8d3f281bbab99500c9fc2f18c453ac295 gstreamer1-plugins-bad-free-debuginfo-1.16.1-4.el8_8.4.x86_64.rpm SHA-256: bab657301b8b65dccb4e1a9b08311d40c86c9a053942b646d035bd8b11ac6750 gstreamer1-plugins-bad-free-debugsource-1.16.1-4.el8_8.4.i686.rpm SHA-256: 184cdada7769593b63320ef41e6966b1996536ce796e3e0c1890ac57816b4177 gstreamer1-plugins-bad-free-debugsource-1.16.1-4.el8_8.4.x86_64.rpm SHA-256: 0663bc07d4620e95886cbaf14fc74a0ce95e3e4fbe7367c594cb2cc8e5ef3b05 Red Hat Enterprise Linux Server - TUS 8.8 SRPM gstreamer1-plugins-bad-free-1.16.1-4.el8_8.4.src.rpm SHA-256: 97187b55720e07e6dc7819b22afc2a209c2bf904061f2f67385a9069aaa9e61c x86_64 gstreamer1-plugins-bad-free-1.16.1-4.el8_8.4.i686.rpm SHA-256: 4a3df1e5235389a88c3ad17e73e93970d814c32c51e2a85330ea7a795c6a22e1 gstreamer1-plugins-bad-free-1.16.1-4.el8_8.4.x86_64.rpm SHA-256: 8aa1591ffdcae2750fbf18802f2f28dde18a91989d8879bc9c0967719201a8b2 gstreamer1-plugins-bad-free-debuginfo-1.16.1-4.el8_8.4.i686.rpm SHA-256: 3cb2a2cc52b2eb8bcd4620863caa20f8d3f281bbab99500c9fc2f18c453ac295 gstreamer1-plugins-bad-free-debuginfo-1.16.1-4.el8_8.4.x86_64.rpm SHA-256: bab657301b8b65dccb4e1a9b08311d40c86c9a053942b646d035bd8b11ac6750 gstreamer1-plugins-bad-free-debugsource-1.16.1-4.el8_8.4.i686.rpm SHA-256: 184cdada7769593b63320ef41e6966b1996536ce796e3e0c1890ac57816b4177 gstreamer1-plugins-bad-free-debugsource-1.16.1-4.el8_8.4.x86_64.rpm SHA-256: 0663bc07d4620e95886cbaf14fc74a0ce95e3e4fbe7367c594cb2cc8e5ef3b05 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.8 SRPM gstreamer1-plugins-bad-free-1.16.1-4.el8_8.4.src.rpm SHA-256: 97187b55720e07e6dc7819b22afc2a209c2bf904061f2f67385a9069aaa9e61c ppc64le gstreamer1-plugins-bad-free-1.16.1-4.el8_8.4.ppc64le.rpm SHA-256: ebcb28a012e175cf85555500bf91881238a9b040a712962d444df7bdeeed8faa gstreamer1-plugins-bad-free-debuginfo-1.16.1-4.el8_8.4.ppc64le.rpm SHA-256: d336f77d85bfc8be86270a80190a73db4cccd6c02bfc5b4b19fe94cc7af1f65e gstreamer1-plugins-bad-free-debugsource-1.16.1-4.el8_8.4.ppc64le.rpm SHA-256: 80109fa3828e03cff3d054c22b52d2847e0b4ebc287498e25a60b736f381cb92 Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.8 SRPM gstreamer1-plugins-bad-free-1.16.1-4.el8_8.4.src.rpm SHA-256: 97187b55720e07e6dc7819b22afc2a209c2bf904061f2f67385a9069aaa9e61c x86_64 gstreamer1-plugins-bad-free-1.16.1-4.el8_8.4.i686.rpm SHA-256: 4a3df1e5235389a88c3ad17e73e93970d814c32c51e2a85330ea7a795c6a22e1 gstreamer1-plugins-bad-free-1.16.1-4.el8_8.4.x86_64.rpm SHA-256: 8aa1591ffdcae2750fbf18802f2f28dde18a91989d8879bc9c0967719201a8b2 gstreamer1-plugins-bad-free-debuginfo-1.16.1-4.el8_8.4.i686.rpm SHA-256: 3cb2a2cc52b2eb8bcd4620863caa20f8d3f281bbab99500c9fc2f18c453ac295 gstreamer1-plugins-bad-free-debuginfo-1.16.1-4.el8_8.4.x86_64.rpm SHA-256: bab657301b8b65dccb4e1a9b08311d40c86c9a053942b646d035bd8b11ac6750 gstreamer1-plugins-bad-free-debugsource-1.16.1-4.el8_8.4.i686.rpm SHA-256: 184cdada7769593b63320ef41e6966b1996536ce796e3e0c1890ac57816b4177 gstreamer1-plugins-bad-free-debugsource-1.16.1-4.el8_8.4.x86_64.rpm SHA-256: 0663bc07d4620e95886cbaf14fc74a0ce95e3e4fbe7367c594cb2cc8e5ef3b05 The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .

Share this article