rpm package
almalinux/gstreamer1-plugins-bad-free-libs
pkg:rpm/almalinux/gstreamer1-plugins-bad-free-libs
Vulnerabilities (16)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-59692 | Hig | 7.5 | < 1.22.12-7.el9_8.3 | 1.22.12-7.el9_8.3 | Jul 9, 2026 | A stack buffer overflow vulnerability was found in GStreamer's DTLS plugin. During a DTLS handshake, the peer certificate Subject Distinguished Name is printed into a fixed-size 2048-byte stack buffer without bounds checking. A remote unauthenticated attacker can send a certifica | |
| CVE-2026-59691 | Hig | 7.1 | < 1.22.12-7.el9_8.3 | 1.22.12-7.el9_8.3 | Jul 9, 2026 | A heap buffer overflow vulnerability was found in GStreamer's rfbsrc plugin. When a client connects to a malicious RFB/VNC server that advertises a 16bpp framebuffer and sends Hextile-encoded updates, the Hextile background fill path writes 32-bit pixel values into a buffer alloc | |
| CVE-2026-52722 | Hig | 7.1 | < 1.26.7-2.el10_2.4 | 1.26.7-2.el10_2.4 | Jun 15, 2026 | A signed integer overflow vulnerability was found in GStreamer's VMnc decoder. A crafted VMnc stream with large cursor dimensions can overflow signed integer payload-size arithmetic, bypassing a length check and leading to out-of-bounds reads. A remote attacker could trick a user | |
| CVE-2026-52720 | Hig | 8.8 | < 1.26.7-2.el10_2.4 | 1.26.7-2.el10_2.4 | Jun 15, 2026 | A heap buffer overflow vulnerability was found in GStreamer's librfb (RFB/VNC client). The rectangle bounds check incorrectly validates area rather than individual dimensions, allowing a malicious VNC server to send a rectangle that extends beyond the framebuffer. A remote attack | |
| CVE-2026-52719 | Hig | 7.1 | < 1.26.7-2.el10_2.4 | 1.26.7-2.el10_2.4 | Jun 15, 2026 | An out-of-bounds read vulnerability was found in the VA JPEG decoder in GStreamer's gst-plugins-bad. The JPEG parser reads a segment length value from the bitstream without validating it against available data. A remote attacker could trick a user into opening a specially crafted | |
| CVE-2026-52718 | Med | 6.5 | < 1.26.7-2.el10_2.4 | 1.26.7-2.el10_2.4 | Jun 15, 2026 | A denial of service vulnerability was found in GStreamer's AV1 codec parser in gst-plugins-bad. The gst_av1_parser_parse_tile_list_obu() function passes a byte count to a bit-reader API that expects a bit count, causing parser desynchronization. A remote attacker could trick a us | |
| CVE-2026-3085 | Hig | 8.8 | < 1.26.7-2.el10_2 | 1.26.7-2.el10_2 | Mar 16, 2026 | GStreamer rtpqdm2depay Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack v | |
| CVE-2026-3083 | Hig | 8.8 | < 1.26.7-2.el10_2 | 1.26.7-2.el10_2 | Mar 16, 2026 | GStreamer rtpqdm2depay Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors | |
| CVE-2026-3082 | Hig | 7.8 | < 1.26.7-2.el10_2 | 1.26.7-2.el10_2 | Mar 16, 2026 | GStreamer JPEG Parser Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack ve | |
| CVE-2026-2923 | Hig | 7.8 | < 1.26.7-2.el10_2 | 1.26.7-2.el10_2 | Mar 16, 2026 | GStreamer DVB Subtitles Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors | |
| CVE-2026-2922 | Hig | 7.8 | < 1.26.7-2.el10_2 | 1.26.7-2.el10_2 | Mar 16, 2026 | GStreamer RealMedia Demuxer Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vec | |
| CVE-2026-2921 | Hig | 7.8 | < 1.26.7-2.el10_2 | 1.26.7-2.el10_2 | Mar 16, 2026 | GStreamer RIFF Palette Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may | |
| CVE-2026-2920 | Hig | 7.8 | < 1.26.7-2.el10_2 | 1.26.7-2.el10_2 | Mar 16, 2026 | GStreamer ASF Demuxer Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack ve | |
| CVE-2025-3887 | Hig | 8.8 | < 1.22.12-4.el9_6 | 1.22.12-4.el9_6 | May 22, 2025 | GStreamer H265 Codec Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but a | |
| CVE-2024-0444 | Hig | 8.8 | < 1.22.12-3.el9 | 1.22.12-3.el9 | Jun 7, 2024 | GStreamer AV1 Video Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but at | |
| CVE-2024-4453 | Hig | 7.8 | < 1.22.12-3.el9 | 1.22.12-3.el9 | May 22, 2024 | GStreamer EXIF Metadata Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack ve |
- affected < 1.22.12-7.el9_8.3fixed 1.22.12-7.el9_8.3
A stack buffer overflow vulnerability was found in GStreamer's DTLS plugin. During a DTLS handshake, the peer certificate Subject Distinguished Name is printed into a fixed-size 2048-byte stack buffer without bounds checking. A remote unauthenticated attacker can send a certifica
- affected < 1.22.12-7.el9_8.3fixed 1.22.12-7.el9_8.3
A heap buffer overflow vulnerability was found in GStreamer's rfbsrc plugin. When a client connects to a malicious RFB/VNC server that advertises a 16bpp framebuffer and sends Hextile-encoded updates, the Hextile background fill path writes 32-bit pixel values into a buffer alloc
- affected < 1.26.7-2.el10_2.4fixed 1.26.7-2.el10_2.4
A signed integer overflow vulnerability was found in GStreamer's VMnc decoder. A crafted VMnc stream with large cursor dimensions can overflow signed integer payload-size arithmetic, bypassing a length check and leading to out-of-bounds reads. A remote attacker could trick a user
- affected < 1.26.7-2.el10_2.4fixed 1.26.7-2.el10_2.4
A heap buffer overflow vulnerability was found in GStreamer's librfb (RFB/VNC client). The rectangle bounds check incorrectly validates area rather than individual dimensions, allowing a malicious VNC server to send a rectangle that extends beyond the framebuffer. A remote attack
- affected < 1.26.7-2.el10_2.4fixed 1.26.7-2.el10_2.4
An out-of-bounds read vulnerability was found in the VA JPEG decoder in GStreamer's gst-plugins-bad. The JPEG parser reads a segment length value from the bitstream without validating it against available data. A remote attacker could trick a user into opening a specially crafted
- affected < 1.26.7-2.el10_2.4fixed 1.26.7-2.el10_2.4
A denial of service vulnerability was found in GStreamer's AV1 codec parser in gst-plugins-bad. The gst_av1_parser_parse_tile_list_obu() function passes a byte count to a bit-reader API that expects a bit count, causing parser desynchronization. A remote attacker could trick a us
- affected < 1.26.7-2.el10_2fixed 1.26.7-2.el10_2
GStreamer rtpqdm2depay Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack v
- affected < 1.26.7-2.el10_2fixed 1.26.7-2.el10_2
GStreamer rtpqdm2depay Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors
- affected < 1.26.7-2.el10_2fixed 1.26.7-2.el10_2
GStreamer JPEG Parser Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack ve
- affected < 1.26.7-2.el10_2fixed 1.26.7-2.el10_2
GStreamer DVB Subtitles Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors
- affected < 1.26.7-2.el10_2fixed 1.26.7-2.el10_2
GStreamer RealMedia Demuxer Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vec
- affected < 1.26.7-2.el10_2fixed 1.26.7-2.el10_2
GStreamer RIFF Palette Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may
- affected < 1.26.7-2.el10_2fixed 1.26.7-2.el10_2
GStreamer ASF Demuxer Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack ve
- affected < 1.22.12-4.el9_6fixed 1.22.12-4.el9_6
GStreamer H265 Codec Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but a
- affected < 1.22.12-3.el9fixed 1.22.12-3.el9
GStreamer AV1 Video Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but at
- affected < 1.22.12-3.el9fixed 1.22.12-3.el9
GStreamer EXIF Metadata Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack ve