RHSA-2026:49603: Important: gstreamer1-plugins-good security update
GStreamer is a streaming media framework based on graphs of filters which operate on media data. The gstreamer1-plugins-good packages contain a collection of well-supported plug-ins of good quality and under the LGPL license.Security Fix(es): gstreamer1-plugins-good: GStreamer: Heap buffer overflow in WavPack decoder via integer overflow (CVE-2026-53705) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Other sources
Important: gstreamer1-plugins-good security update
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/gstreamer1-plugins-goodto a version that resolves this vulnerability.Fixed in 1.10.4-4.el7_9.1 - Upgrade
Upgrade
redhat/gstreamer1-plugins-good-debuginfoto a version that resolves this vulnerability.Fixed in 1.10.4-4.el7_9.1
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:49603?
The severity of RHSA-2026:49603 is high with a score of 7.
How do I fix RHSA-2026:49603?
To address RHSA-2026:49603, update the gstreamer1-plugins-good package to the latest version provided in the security advisory.
What type of vulnerability is identified in RHSA-2026:49603?
RHSA-2026:49603 is associated with a heap buffer overflow vulnerability in the GStreamer framework.
What software is affected by RHSA-2026:49603?
The affected software includes the gstreamer1-plugins-good and gstreamer1-plugins-good-debuginfo packages.
Which systems are impacted by RHSA-2026:49603?
RHSA-2026:49603 impacts Red Hat Enterprise Linux Server and its Extended Life Cycle Support versions for IBM z Systems and IBM Power.