RHSA-2026:70264MediumCVSS 7.5

Red Hat Security Advisory: gstreamer1-plugins-good security update

Published
September 22, 2026
Last Modified
September 23, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2026-18649 — gstreamer1-plugins-good: gst-plugins-good: unbounded memory growth in rtph264depay and rtph265depay RTP depayloaders CVE-2026-73433 — gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux FUJIFILM strd parsing leading to out-of-bounds read/write CVE-2026-73434 — gstreamer1-plugins-good: gstreamer: out-of-bounds read in avidemux vprp video field descriptor parsing

🎯 Affected products16

  • Red Hat Enterprise Linux Server (v. 7 ELS)
  • gstreamer1-plugins-good-0:1.10.4-4.el7_9.3.i686 as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
  • gstreamer1-plugins-good-0:1.10.4-4.el7_9.3.ppc as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
  • gstreamer1-plugins-good-0:1.10.4-4.el7_9.3.ppc64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
  • gstreamer1-plugins-good-0:1.10.4-4.el7_9.3.ppc64le as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
  • gstreamer1-plugins-good-0:1.10.4-4.el7_9.3.s390 as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
  • gstreamer1-plugins-good-0:1.10.4-4.el7_9.3.s390x as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
  • gstreamer1-plugins-good-0:1.10.4-4.el7_9.3.src as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
  • gstreamer1-plugins-good-0:1.10.4-4.el7_9.3.x86_64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
  • gstreamer1-plugins-good-debuginfo-0:1.10.4-4.el7_9.3.i686 as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
  • gstreamer1-plugins-good-debuginfo-0:1.10.4-4.el7_9.3.ppc as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
  • gstreamer1-plugins-good-debuginfo-0:1.10.4-4.el7_9.3.ppc64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
  • gstreamer1-plugins-good-debuginfo-0:1.10.4-4.el7_9.3.ppc64le as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
  • gstreamer1-plugins-good-debuginfo-0:1.10.4-4.el7_9.3.s390 as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
  • gstreamer1-plugins-good-debuginfo-0:1.10.4-4.el7_9.3.s390x as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
  • gstreamer1-plugins-good-debuginfo-0:1.10.4-4.el7_9.3.x86_64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS)

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: The following mitigations can reduce risk before a patch is available: 1. Use SRTP or DTLS-SRTP: Deploy the srtpdec element in the pipeline before the depayloader. SRTP provides per-packet authentication and will reject unauthenticated fragments before they reach rtph264depay/rtph265depay, completely preventing exploitation. 2. Network-level restriction: Use firewall rules (iptables/nftables) to restrict which sources can send RTP traffic to the GStreamer process. Allow RTP only from trusted, authenticated peers. 3. Build-time exclusion: Disable the entire RTP plugin by configuring with "-Drtp=disabled" in meson build options. This removes all RTP functionality including the vulnerable depayloaders. 4. Runtime element exclusion: Prevent the affected elements from being auto-plugged by setting GST_PLUGIN_FEATURE_RANK=rtph264depay:0,rtph265depay:0. This prevents automatic selection but not explicit pipeline construction.

🔗 References (6)