RHSA-2026:50688: Moderate: gstreamer1-plugins-ugly-free security update
GStreamer is a streaming media framework, based on graphs of elements which operate on media data. This package contains plug-ins whose license is not fully compatible with LGPL.Security Fix(es): gstreamer1-plugins-ugly-free: GStreamer: Out-of-bounds read in RealMedia demuxer audio stream header parser (CVE-2026-53703) gstreamer1-plugins-ugly-free: GStreamer: Out-of-bounds read in RealMedia demuxer FILEINFO metadata parser (CVE-2026-53704) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Other sources
Moderate: gstreamer1-plugins-ugly-free security update
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/gstreamer1-plugins-ugly-freeto a version that resolves this vulnerability.Fixed in 1.24.11-1.el10_0.2 - Upgrade
Upgrade
redhat/gstreamer1-plugins-ugly-free-debuginfoto a version that resolves this vulnerability.Fixed in 1.24.11-1.el10_0.2 - Upgrade
Upgrade
redhat/gstreamer1-plugins-ugly-free-debugsourceto a version that resolves this vulnerability.Fixed in 1.24.11-1.el10_0.2 - Upgrade
Upgrade
redhat/gstreamer1-plugins-ugly-freeto a version that resolves this vulnerability.Fixed in 1.24.11-1.el10_0.2.aa - Upgrade
Upgrade
redhat/gstreamer1-plugins-ugly-free-debuginfoto a version that resolves this vulnerability.Fixed in 1.24.11-1.el10_0.2.aa - Upgrade
Upgrade
redhat/gstreamer1-plugins-ugly-free-debugsourceto a version that resolves this vulnerability.Fixed in 1.24.11-1.el10_0.2.aa - Upgrade
Upgrade
gstreamer1-plugins-ugly-freeto a version that resolves this vulnerability.Patch CVE-2026-53704 - Upgrade
Upgrade
gstreamer1-plugins-ugly-freeto a version that resolves this vulnerability.Patch CVE-2026-53703