RHSA-2026:19024HighCVSS 8.8

Red Hat Security Advisory: gstreamer1-plugins-bad-free, gstreamer1-plugins-base, gstreamer1-plugins-good, and gstreamer1-plugins-ugly-free security update

Published
May 19, 2026
Last Modified
July 20, 2026

🔗 CVE IDs covered (7)

📋 Description

CVE-2026-2920 — gstreamer-plugins-ugly: GStreamer: Arbitrary code execution via ASF file processing CVE-2026-2921 — gstreamer-plugins-base: GStreamer: Arbitrary code execution via RIFF palette integer overflow in AVI file handling CVE-2026-2922 — gstreamer-plugins-ugly: GStreamer: Remote Code Execution via out-of-bounds write in RealMedia Demuxer CVE-2026-2923 — gstreamer-plugins-bad: GStreamer: Remote Code Execution via out-of-bounds write in DVB Subtitles handling CVE-2026-3082 — gstreamer-plugins-bad: GStreamer: Remote Code Execution via heap-based buffer overflow in JPEG parser CVE-2026-3083 — gstreamer-plugins-good: GStreamer: Remote Code Execution via Out-Of-Bounds Write in rtpqdm2depay CVE-2026-3085 — gstreamer-plugins-good: GStreamer: Remote Code Execution via Heap-based Buffer Overflow in rtpqdm2depay

🔗 References (10)