{"id":"ALSA-2026:36749","summary":"Important: gstreamer1-plugins-bad-free security update","details":"GStreamer is a streaming media framework based on graphs of filters which operate on media data. The gstreamer1-plugins-bad-free package contains a collection of plug-ins for GStreamer.  \n\nSecurity Fix(es):  \n\n  * gstreamer1-plugins-bad-free: GStreamer: Denial of service via AV1 tile_list_obu parser byte/bit confusion (CVE-2026-52718)\n  * gstreamer1-plugins-bad-free: GStreamer: Out-of-bounds read via JPEG segment length validation in VA decoder (CVE-2026-52719)\n  * gstreamer1-plugins-bad-free: GStreamer: Heap buffer overflow via crafted VNC server rectangle in librfb (CVE-2026-52720)\n  * gstreamer1-plugins-bad-free: GStreamer: Signed integer overflow in VMnc decoder cursor payload handling (CVE-2026-52722)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n","modified":"2026-07-09T14:15:04.530301858Z","published":"2026-07-08T00:00:00Z","related":["CVE-2026-52718","CVE-2026-52719","CVE-2026-52720","CVE-2026-52722"],"references":[{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:36749"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-52718"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-52719"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-52720"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-52722"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2486328"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2486353"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2486731"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2486733"},{"type":"ADVISORY","url":"https://errata.almalinux.org/10/ALSA-2026-36749.html"}],"affected":[{"package":{"name":"gstreamer1-plugins-bad-free","ecosystem":"AlmaLinux:10","purl":"pkg:rpm/almalinux/gstreamer1-plugins-bad-free"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.26.7-2.el10_2.4"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux10/ALSA-2026:36749.json"}},{"package":{"name":"gstreamer1-plugins-bad-free-devel","ecosystem":"AlmaLinux:10","purl":"pkg:rpm/almalinux/gstreamer1-plugins-bad-free-devel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.26.7-2.el10_2.4"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux10/ALSA-2026:36749.json"}},{"package":{"name":"gstreamer1-plugins-bad-free-libs","ecosystem":"AlmaLinux:10","purl":"pkg:rpm/almalinux/gstreamer1-plugins-bad-free-libs"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.26.7-2.el10_2.4"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux10/ALSA-2026:36749.json"}}],"schema_version":"1.7.5"}