- What: Security update for gstreamer-plugins-bad-free
- Impact: Red Hat Enterprise Linux 7 systems may be affected
Red Hat Product Errata RHSA-2026:62532 - Security Advisory Issued: 2026-09-02 Updated: 2026-09-02 RHSA-2026:62532 - Security Advisory Overview Updated Packages Synopsis Important: gstreamer-plugins-bad-free security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for gstreamer-plugins-bad-free is now available for Red Hat Enterprise Linux 7 Extended Lifecycle Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description GStreamer is a streaming media framework based on graphs of filters which operate on media data. The gstreamer-plugins-bad-free package contains a collection of plug-ins for GStreamer. Security Fix(es): gstreamer: gstreamer: rfbsrc/librfb Hextile heap out-of-bounds write with 16bpp framebuffer (CVE-2026-59691) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux Server - Extended Life Cycle Support 7 x86_64 Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 7 s390x Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian 7 ppc64 Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian 7 ppc64le Fixes BZ - 2497343 - CVE-2026-59691 gstreamer: gstreamer: rfbsrc/librfb Hextile heap out-of-bounds write with 16bpp framebuffer CVEs CVE-2026-59691 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux Server - Extended Life Cycle Support 7 SRPM gstreamer-plugins-bad-free-0.10.23-26.el7_9.src.rpm SHA-256: cee49a4b41d60f375d22b1b6d3895e1176af91366726e8c6064ded3bc7ede0d4 x86_64 gstreamer-plugins-bad-free-0.10.23-26.el7_9.i686.rpm SHA-256: a7c0246ba9174f10d5c6aac0e407b03f55ba220dda9f3d994e3360eb266af18e gstreamer-plugins-bad-free-0.10.23-26.el7_9.x86_64.rpm SHA-256: 2851246f1ff5f89d0e5125a335c991754fdf9cec6984a279d44d979e271bb0b8 gstreamer-plugins-bad-free-debuginfo-0.10.23-26.el7_9.i686.rpm SHA-256: 1ffbf7f7dd2dc20f7e224aaddcd2838a0a66675bad3f7059927a8426ed7590cf gstreamer-plugins-bad-free-debuginfo-0.10.23-26.el7_9.i686.rpm SHA-256: 1ffbf7f7dd2dc20f7e224aaddcd2838a0a66675bad3f7059927a8426ed7590cf gstreamer-plugins-bad-free-debuginfo-0.10.23-26.el7_9.x86_64.rpm SHA-256: 62c2a00ab41e847e045889c397926a779c98eaef104091bdf36dd65716524c66 gstreamer-plugins-bad-free-debuginfo-0.10.23-26.el7_9.x86_64.rpm SHA-256: 62c2a00ab41e847e045889c397926a779c98eaef104091bdf36dd65716524c66 gstreamer-plugins-bad-free-devel-0.10.23-26.el7_9.i686.rpm SHA-256: 017a916caeff1f02fbccdd89098ddc516605d97972f0fb1518a8179d93e9c979 gstreamer-plugins-bad-free-devel-0.10.23-26.el7_9.x86_64.rpm SHA-256: 0fc1a69b368ac355b8d8a56c3997eba463e350ed4d4d840011d3faf1d502e4d6 gstreamer-plugins-bad-free-devel-docs-0.10.23-26.el7_9.x86_64.rpm SHA-256: f2dadb92283c148d3520253ec733df2abb72bb629e18bd913ba65239eca5cb7d Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 7 SRPM gstreamer-plugins-bad-free-0.10.23-26.el7_9.src.rpm SHA-256: cee49a4b41d60f375d22b1b6d3895e1176af91366726e8c6064ded3bc7ede0d4 s390x gstreamer-plugins-bad-free-0.10.23-26.el7_9.s390.rpm SHA-256: bfbb7c3e5c780426e99699733ef8c2b1ed340ed0002b0b6bb001fad8cdbf0ee9 gstreamer-plugins-bad-free-0.10.23-26.el7_9.s390x.rpm SHA-256: 261393434b9a430e101189e13030ba631704e383fa63679a007bd68be5d682b6 gstreamer-plugins-bad-free-debuginfo-0.10.23-26.el7_9.s390.rpm SHA-256: 2316a6a3c2752fb53d6cc27cfbadf7d4dc81cf07af1fd715043b13ab766d7daa gstreamer-plugins-bad-free-debuginfo-0.10.23-26.el7_9.s390.rpm SHA-256: 2316a6a3c2752fb53d6cc27cfbadf7d4dc81cf07af1fd715043b13ab766d7daa gstreamer-plugins-bad-free-debuginfo-0.10.23-26.el7_9.s390x.rpm SHA-256: ca2096ef9a0b8ecc94a1fa2251a8c439b599ed7af82380928b40688c6fee8c1f gstreamer-plugins-bad-free-debuginfo-0.10.23-26.el7_9.s390x.rpm SHA-256: ca2096ef9a0b8ecc94a1fa2251a8c439b599ed7af82380928b40688c6fee8c1f gstreamer-plugins-bad-free-devel-0.10.23-26.el7_9.s390.rpm SHA-256: ea3941f1710d26a2831e9bc4f7636536bc08caa88197b56b357dd42169a6c029 gstreamer-plugins-bad-free-devel-0.10.23-26.el7_9.s390x.rpm SHA-256: d6a356f4b108b66354c667b412f319f81ea63b3f23b0670d407ad6e8ff495fc1 gstreamer-plugins-bad-free-devel-docs-0.10.23-26.el7_9.s390x.rpm SHA-256: 467643a51b0b611995511041ef5864e77eab31cb08ed56030064903c05826d64 Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian 7 SRPM gstreamer-plugins-bad-free-0.10.23-26.el7_9.src.rpm SHA-256: cee49a4b41d60f375d22b1b6d3895e1176af91366726e8c6064ded3bc7ede0d4 ppc64 gstreamer-plugins-bad-free-0.10.23-26.el7_9.ppc.rpm SHA-256: 9a6f555aeca54a4ff0fbdae63df0df2024c1400841fff517b76ec8abd9cde535 gstreamer-plugins-bad-free-0.10.23-26.el7_9.ppc64.rpm SHA-256: b3f6db7a296b9b12499c10b21b86cb094f580cf86370b89ab50f6cf4d306329c gstreamer-plugins-bad-free-debuginfo-0.10.23-26.el7_9.ppc.rpm SHA-256: c4faec5d7f9015cec5c3900bfac1f0992450c642926f9dbc5b401423ee92584f gstreamer-plugins-bad-free-debuginfo-0.10.23-26.el7_9.ppc.rpm SHA-256: c4faec5d7f9015cec5c3900bfac1f0992450c642926f9dbc5b401423ee92584f gstreamer-plugins-bad-free-debuginfo-0.10.23-26.el7_9.ppc64.rpm SHA-256: 553f9ee75146c8e207bab9dac3ba4168a9aa1d25d8bee06c866a2a05c4918b0e gstreamer-plugins-bad-free-debuginfo-0.10.23-26.el7_9.ppc64.rpm SHA-256: 553f9ee75146c8e207bab9dac3ba4168a9aa1d25d8bee06c866a2a05c4918b0e gstreamer-plugins-bad-free-devel-0.10.23-26.el7_9.ppc.rpm SHA-256: d681a5341002570fb40d8ccae7e3a5b4c3a0d65faf87df86b2e39ea0c3a2566b gstreamer-plugins-bad-free-devel-0.10.23-26.el7_9.ppc64.rpm SHA-256: 33c5b28c34bba108e2fbd8b2c2483c9f8175e814b106bd1cc4d58902844f6311 gstreamer-plugins-bad-free-devel-docs-0.10.23-26.el7_9.ppc64.rpm SHA-256: 4840d10e01437f684e877c41a913950f489dbdb9aa76bc86eacf47fd05234f1c Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian 7 SRPM gstreamer-plugins-bad-free-0.10.23-26.el7_9.src.rpm SHA-256: cee49a4b41d60f375d22b1b6d3895e1176af91366726e8c6064ded3bc7ede0d4 ppc64le gstreamer-plugins-bad-free-0.10.23-26.el7_9.ppc64le.rpm SHA-256: da4510035a159c623b8be90a2d122b3cf56e438ef1c03b3489b2d90cfba0d927 gstreamer-plugins-bad-free-debuginfo-0.10.23-26.el7_9.ppc64le.rpm SHA-256: bf8ddba1dc01359dcf365201532a4428f6c701a763a59802f1a122fe9f273676 gstreamer-plugins-bad-free-debuginfo-0.10.23-26.el7_9.ppc64le.rpm SHA-256: bf8ddba1dc01359dcf365201532a4428f6c701a763a59802f1a122fe9f273676 gstreamer-plugins-bad-free-devel-0.10.23-26.el7_9.ppc64le.rpm SHA-256: 01165b119a2ac98ce0d7c17fffb1bcd4bbc5291299b8af056c69ef2d0423ab30 gstreamer-plugins-bad-free-devel-docs-0.10.23-26.el7_9.ppc64le.rpm SHA-256: a50d2eeb56d31f5deeeaa73c39afc1c2967f832baf321ac630aed77609dd3298 The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .