RHSA-2026:36673: Moderate: gstreamer1-plugins-ugly-free security update
GStreamer is a streaming media framework, based on graphs of elements which operate on media data. This package contains plug-ins whose license is not fully compatible with LGPL.Security Fix(es): gstreamer1-plugins-ugly-free: GStreamer: Out-of-bounds read in RealMedia demuxer audio stream header parser (CVE-2026-53703) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Other sources
Moderate: gstreamer1-plugins-ugly-free security update
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/gstreamer1-plugins-ugly-freeto a version that resolves this vulnerability.Fixed in 1.26.7-2.el10_2.1 - Upgrade
Upgrade
redhat/gstreamer1-plugins-ugly-free-debuginfoto a version that resolves this vulnerability.Fixed in 1.26.7-2.el10_2.1 - Upgrade
Upgrade
redhat/gstreamer1-plugins-ugly-free-debugsourceto a version that resolves this vulnerability.Fixed in 1.26.7-2.el10_2.1 - Upgrade
Upgrade
redhat/gstreamer1-plugins-ugly-freeto a version that resolves this vulnerability.Fixed in 1.26.7-2.el10_2.1.aa - Upgrade
Upgrade
redhat/gstreamer1-plugins-ugly-free-debuginfoto a version that resolves this vulnerability.Fixed in 1.26.7-2.el10_2.1.aa - Upgrade
Upgrade
redhat/gstreamer1-plugins-ugly-free-debugsourceto a version that resolves this vulnerability.Fixed in 1.26.7-2.el10_2.1.aa
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:36673?
The severity of RHSA-2026:36673 is classified as medium.
What is the risk associated with RHSA-2026:36673?
The risk associated with RHSA-2026:36673 is rated at 19.
How do I fix RHSA-2026:36673?
To fix RHSA-2026:36673, you need to update the GStreamer1-plugins-ugly-free package to the latest version.
What vulnerabilities does RHSA-2026:36673 address?
RHSA-2026:36673 addresses an out-of-bounds read vulnerability in the RealMedia demuxer audio stream header.
Which software packages are affected by RHSA-2026:36673?
The affected software packages include gstreamer1-plugins-ugly-free, gstreamer1-plugins-ugly-free-debuginfo, and gstreamer1-plugins-ugly-free-debugsource.