https://seclists.org/oss-sec/2026/q2/320: 10+ CVEs in GStamer
Published May 1, 2026
·Updated
Affected Software
6 affected components
GStreamer GStreamer
Gnome localsearch (tracker-miners)
Gnome tracker-extract
Gnome Nautilus (GNOME Files)
Gnome GNOME Videos
Gnome Rhythmbox
Frequently Asked Questions
1
What is the severity of CVE-2023-43641?
CVE-2023-43641 is considered a critical vulnerability due to its potential for sandbox escape.
2
How do I fix CVE-2023-43641?
To mitigate CVE-2023-43641, ensure you are using the latest version of GStreamer which contains security patches.
3
What impact does CVE-2023-43641 have on GStreamer?
CVE-2023-43641 allows attackers to escape from the GStreamer sandbox, potentially leading to arbitrary code execution.
4
Is CVE-2023-43641 related to any other vulnerabilities?
Yes, CVE-2023-43641 is related to CVE-2023-5557, which also involved sandboxing issues in GStreamer.
5
Who is affected by CVE-2023-43641?
Users of GStreamer and related GNOME applications such as Nautilus and Rhythmbox are at risk from CVE-2023-43641.