RHSA-2026:36674: Moderate: gstreamer1-plugins-ugly-free security update
GStreamer is a streaming media framework, based on graphs of elements which operate on media data. This package contains plug-ins whose license is not fully compatible with LGPL.Security Fix(es): gstreamer1-plugins-ugly-free: GStreamer: Out-of-bounds read in RealMedia demuxer audio stream header parser (CVE-2026-53703) gstreamer1-plugins-ugly-free: GStreamer: Out-of-bounds read in RealMedia demuxer FILEINFO metadata parser (CVE-2026-53704) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Other sources
Moderate: gstreamer1-plugins-ugly-free security update
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/gstreamer1-plugins-ugly-freeto a version that resolves this vulnerability.Fixed in 1.22.12-6.el9_8.1 - Upgrade
Upgrade
redhat/gstreamer1-plugins-ugly-free-debuginfoto a version that resolves this vulnerability.Fixed in 1.22.12-6.el9_8.1 - Upgrade
Upgrade
redhat/gstreamer1-plugins-ugly-free-debugsourceto a version that resolves this vulnerability.Fixed in 1.22.12-6.el9_8.1 - Upgrade
Upgrade
redhat/gstreamer1-plugins-ugly-freeto a version that resolves this vulnerability.Fixed in 1.22.12-6.el9_8.1.aa - Upgrade
Upgrade
redhat/gstreamer1-plugins-ugly-free-debuginfoto a version that resolves this vulnerability.Fixed in 1.22.12-6.el9_8.1.aa - Upgrade
Upgrade
redhat/gstreamer1-plugins-ugly-free-debugsourceto a version that resolves this vulnerability.Fixed in 1.22.12-6.el9_8.1.aa - Upgrade
Upgrade
gstreamer1-plugins-ugly-freeto a version that resolves this vulnerability.Patch CVE-2026-53704 - Upgrade
Upgrade
gstreamer1-plugins-ugly-freeto a version that resolves this vulnerability.Patch CVE-2026-53703
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:36674?
The severity of RHSA-2026:36674 is medium, with a score of 4.
What software is affected by RHSA-2026:36674?
RHSA-2026:36674 affects various Red Hat Enterprise Linux versions including Power, x86_64, and ARM 64.
How do I fix RHSA-2026:36674?
To fix RHSA-2026:36674, you should update the gstreamer1-plugins-ugly package to the latest version available for your Red Hat environment.
What does the gstreamer1-plugins-ugly update address in RHSA-2026:36674?
The gstreamer1-plugins-ugly update in RHSA-2026:36674 addresses security vulnerabilities associated with the package.
When was RHSA-2026:36674 published?
RHSA-2026:36674 was published on July 8, 2026.