RHSA-2026:50691: Moderate: gstreamer1-plugins-ugly-free security update
GStreamer is a streaming media framework, based on graphs of elements which operate on media data. This package contains plug-ins whose license is not fully compatible with LGPL.Security Fix(es): gstreamer1-plugins-ugly-free: GStreamer: Out-of-bounds read in RealMedia demuxer audio stream header parser (CVE-2026-53703) gstreamer1-plugins-ugly-free: GStreamer: Out-of-bounds read in RealMedia demuxer FILEINFO metadata parser (CVE-2026-53704) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Other sources
Moderate: gstreamer1-plugins-ugly-free security update
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/gstreamer1-plugins-ugly-freeto a version that resolves this vulnerability.Fixed in 1.22.12-4.el9_6.1 - Upgrade
Upgrade
redhat/gstreamer1-plugins-ugly-free-debuginfoto a version that resolves this vulnerability.Fixed in 1.22.12-4.el9_6.1 - Upgrade
Upgrade
redhat/gstreamer1-plugins-ugly-free-debugsourceto a version that resolves this vulnerability.Fixed in 1.22.12-4.el9_6.1 - Upgrade
Upgrade
redhat/gstreamer1-plugins-ugly-freeto a version that resolves this vulnerability.Fixed in 1.22.12-4.el9_6.1.aa - Upgrade
Upgrade
redhat/gstreamer1-plugins-ugly-free-debuginfoto a version that resolves this vulnerability.Fixed in 1.22.12-4.el9_6.1.aa - Upgrade
Upgrade
redhat/gstreamer1-plugins-ugly-free-debugsourceto a version that resolves this vulnerability.Fixed in 1.22.12-4.el9_6.1.aa - Upgrade
Upgrade
gstreamer1-plugins-ugly-freeto a version that resolves this vulnerability.Patch CVE-2026-53704 - Upgrade
Upgrade
gstreamer1-plugins-ugly-freeto a version that resolves this vulnerability.Patch CVE-2026-53703
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:50691?
The severity of RHSA-2026:50691 is medium, rated at level 4.
What are the security fixes addressed in RHSA-2026:50691?
RHSA-2026:50691 addresses an out-of-bounds read vulnerability in the RealMedia demuxer audio stream header.
How do I fix RHSA-2026:50691?
To fix RHSA-2026:50691, update the gstreamer1-plugins-ugly-free package to the latest version available from Red Hat.
Which systems are affected by RHSA-2026:50691?
RHSA-2026:50691 affects various versions of Red Hat Enterprise Linux, including those for Power LE and x86_64 architectures.
Is gstreamer1-plugins-ugly-free necessary for my Red Hat system?
gstreamer1-plugins-ugly-free is a set of plugins for GStreamer, but depending on your media handling needs, it may or may not be essential.