RHSA-2026:50688: Moderate: gstreamer1-plugins-ugly-free security update
GStreamer is a streaming media framework, based on graphs of elements which operate on media data. This package contains plug-ins whose license is not fully compatible with LGPL.Security Fix(es): gstreamer1-plugins-ugly-free: GStreamer: Out-of-bounds read in RealMedia demuxer audio stream header parser (CVE-2026-53703) gstreamer1-plugins-ugly-free: GStreamer: Out-of-bounds read in RealMedia demuxer FILEINFO metadata parser (CVE-2026-53704) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Other sources
Moderate: gstreamer1-plugins-ugly-free security update
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/gstreamer1-plugins-ugly-freeto a version that resolves this vulnerability.Fixed in 1.24.11-1.el10_0.2 - Upgrade
Upgrade
redhat/gstreamer1-plugins-ugly-free-debuginfoto a version that resolves this vulnerability.Fixed in 1.24.11-1.el10_0.2 - Upgrade
Upgrade
redhat/gstreamer1-plugins-ugly-free-debugsourceto a version that resolves this vulnerability.Fixed in 1.24.11-1.el10_0.2 - Upgrade
Upgrade
redhat/gstreamer1-plugins-ugly-freeto a version that resolves this vulnerability.Fixed in 1.24.11-1.el10_0.2.aa - Upgrade
Upgrade
redhat/gstreamer1-plugins-ugly-free-debuginfoto a version that resolves this vulnerability.Fixed in 1.24.11-1.el10_0.2.aa - Upgrade
Upgrade
redhat/gstreamer1-plugins-ugly-free-debugsourceto a version that resolves this vulnerability.Fixed in 1.24.11-1.el10_0.2.aa - Upgrade
Upgrade
gstreamer1-plugins-ugly-freeto a version that resolves this vulnerability.Patch CVE-2026-53704 - Upgrade
Upgrade
gstreamer1-plugins-ugly-freeto a version that resolves this vulnerability.Patch CVE-2026-53703
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:50688?
The severity of RHSA-2026:50688 is categorized as medium, with a score of 4.
How do I fix RHSA-2026:50688?
To fix RHSA-2026:50688, update the gstreamer1-plugins-ugly-free package to the latest security release.
What vulnerability does RHSA-2026:50688 address?
RHSA-2026:50688 addresses an out-of-bounds read issue in the RealMedia demuxer's audio stream header processing.
Which software is affected by RHSA-2026:50688?
The affected software includes the gstreamer1-plugins-ugly-free, gstreamer1-plugins-ugly-free-debuginfo, and gstreamer1-plugins-ugly-free-debugsource packages.
What impact does RHSA-2026:50688 have on my system?
The impact of RHSA-2026:50688 could potentially allow unauthorized read access to memory, which might lead to information leakage.