gstreamer1-plugins-bad-free-1.16.1-5.el8_10

エラータID: AXSA:2025-9964:01

Release date: 
Wednesday, May 28, 2025 - 13:50
Subject: 
gstreamer1-plugins-bad-free-1.16.1-5.el8_10
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
High
Description: 

GStreamer is a streaming media framework based on graphs of filters which operate on media data. The gstreamer1-plugins-bad-free package contains a collection of plug-ins for GStreamer.

Security Fix(es):

* GStreamer: GStreamer H265 Codec Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability (CVE-2025-3887)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2025-3887
GStreamer H265 Codec Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of H265 slice headers. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-26596.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. gstreamer1-plugins-bad-free-1.16.1-5.el8_10.src.rpm
    MD5: c95b976709d02440bc862bb214d14a09
    SHA-256: 9593c7012824ed9ac07fa2f61bd691395ec44b600f4da8d39d3be63c25b47287
    Size: 5.03 MB

Asianux Server 8 for x86_64
  1. gstreamer1-plugins-bad-free-1.16.1-5.el8_10.i686.rpm
    MD5: fb74f7cbdd5f91f0c8d30ab7a1d77f81
    SHA-256: f29d11b379f9681e19f1b7b2b83a8339e2524517ae25d0414315f76653d7f307
    Size: 1.91 MB
  2. gstreamer1-plugins-bad-free-1.16.1-5.el8_10.x86_64.rpm
    MD5: 27032b80d76a305fc0af786c8e39a3f5
    SHA-256: 45bd1d0a165c8b79d9d8e260165a9eb2d3cfffae1720fb6d907912a03675ec2f
    Size: 1.83 MB
  3. gstreamer1-plugins-bad-free-devel-1.16.1-5.el8_10.i686.rpm
    MD5: 509c1bd1a3c147b525901eb62833ef2a
    SHA-256: cbe978af688d874c06a4eacc9162a8a193ef3509c2eab84a68c8c5b31f4bbec5
    Size: 525.48 kB
  4. gstreamer1-plugins-bad-free-devel-1.16.1-5.el8_10.x86_64.rpm
    MD5: 0078922dd4e04e663f5d1969c092482d
    SHA-256: 6e3098a34754db3f3e0b99e69b7dcd65b11b77ffa76bc3ddb8d21c10241385c2
    Size: 525.55 kB