RHSA-2025:18416MediumCVSS 7.8
Red Hat Security Advisory: Automotive bug fix and enhancement update
🔗 CVE IDs covered (2)
📋 Description
CVE-2024-0444 — gstreamer: AV1 Video Parsing Stack-based Buffer Overflow CVE-2024-4453 — gstreamer: EXIF Metadata Parsing Integer Overflow
🎯 Affected products39
- Red Hat In-Vehicle-OS Variant
- gstreamer1-0:1.22.12-3.el9.aarch64 as a component of Red Hat In-Vehicle-OS Variant
- gstreamer1-0:1.22.12-3.el9.src as a component of Red Hat In-Vehicle-OS Variant
- gstreamer1-0:1.22.12-3.el9.x86_64 as a component of Red Hat In-Vehicle-OS Variant
- gstreamer1-debuginfo-0:1.22.12-3.el9.aarch64 as a component of Red Hat In-Vehicle-OS Variant
- gstreamer1-debuginfo-0:1.22.12-3.el9.x86_64 as a component of Red Hat In-Vehicle-OS Variant
- gstreamer1-debugsource-0:1.22.12-3.el9.aarch64 as a component of Red Hat In-Vehicle-OS Variant
- gstreamer1-debugsource-0:1.22.12-3.el9.x86_64 as a component of Red Hat In-Vehicle-OS Variant
- gstreamer1-devel-0:1.22.12-3.el9.aarch64 as a component of Red Hat In-Vehicle-OS Variant
- gstreamer1-devel-0:1.22.12-3.el9.x86_64 as a component of Red Hat In-Vehicle-OS Variant
- gstreamer1-plugins-bad-free-0:1.22.12-3.el9.aarch64 as a component of Red Hat In-Vehicle-OS Variant
- gstreamer1-plugins-bad-free-0:1.22.12-3.el9.src as a component of Red Hat In-Vehicle-OS Variant
- gstreamer1-plugins-bad-free-0:1.22.12-3.el9.x86_64 as a component of Red Hat In-Vehicle-OS Variant
- gstreamer1-plugins-bad-free-debuginfo-0:1.22.12-3.el9.aarch64 as a component of Red Hat In-Vehicle-OS Variant
- gstreamer1-plugins-bad-free-debuginfo-0:1.22.12-3.el9.x86_64 as a component of Red Hat In-Vehicle-OS Variant
- gstreamer1-plugins-bad-free-debugsource-0:1.22.12-3.el9.aarch64 as a component of Red Hat In-Vehicle-OS Variant
- gstreamer1-plugins-bad-free-debugsource-0:1.22.12-3.el9.x86_64 as a component of Red Hat In-Vehicle-OS Variant
- gstreamer1-plugins-bad-free-devel-0:1.22.12-3.el9.aarch64 as a component of Red Hat In-Vehicle-OS Variant
- gstreamer1-plugins-bad-free-devel-0:1.22.12-3.el9.x86_64 as a component of Red Hat In-Vehicle-OS Variant
- gstreamer1-plugins-bad-free-libs-0:1.22.12-3.el9.aarch64 as a component of Red Hat In-Vehicle-OS Variant
- gstreamer1-plugins-bad-free-libs-0:1.22.12-3.el9.x86_64 as a component of Red Hat In-Vehicle-OS Variant
- gstreamer1-plugins-bad-free-libs-debuginfo-0:1.22.12-3.el9.aarch64 as a component of Red Hat In-Vehicle-OS Variant
- gstreamer1-plugins-bad-free-libs-debuginfo-0:1.22.12-3.el9.x86_64 as a component of Red Hat In-Vehicle-OS Variant
- gstreamer1-plugins-ugly-free-0:1.22.12-3.el9.aarch64 as a component of Red Hat In-Vehicle-OS Variant
- gstreamer1-plugins-ugly-free-0:1.22.12-3.el9.src as a component of Red Hat In-Vehicle-OS Variant
- gstreamer1-plugins-ugly-free-0:1.22.12-3.el9.x86_64 as a component of Red Hat In-Vehicle-OS Variant
- gstreamer1-plugins-ugly-free-debuginfo-0:1.22.12-3.el9.aarch64 as a component of Red Hat In-Vehicle-OS Variant
- gstreamer1-plugins-ugly-free-debuginfo-0:1.22.12-3.el9.x86_64 as a component of Red Hat In-Vehicle-OS Variant
- gstreamer1-plugins-ugly-free-debugsource-0:1.22.12-3.el9.aarch64 as a component of Red Hat In-Vehicle-OS Variant
- gstreamer1-plugins-ugly-free-debugsource-0:1.22.12-3.el9.x86_64 as a component of Red Hat In-Vehicle-OS Variant
- +9 more not shown
✅ Remediation
To update your implementation of Red Hat In-Vehicle Operating System,contact Red Hat Support: https://access.redhat.com/support. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2025:18416
- externalhttps://docs.redhat.com/en/documentation/red_hat_in_vehicle_os/1.0/html/1.0_release_notes/index
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://docs.redhat.com/en/documentation/red_hat_enterprise_linux/9/html/9.6_release_notes/indexhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2282999
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2292335
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_18416.json