gstreamer1-plugins-bad-free-1.22.12-7.el9_8.1
エラータID: AXSA:2026-1479:03
リリース日:
2026/08/07 Friday - 15:07
題名:
gstreamer1-plugins-bad-free-1.22.12-7.el9_8.1
影響のあるチャネル:
MIRACLE LINUX 9 for x86_64
Severity:
High
Description:
以下項目について対処しました。
[Security Fix]
- GStreamer の gst-plugins-bad に含まれる AV1 codec parser には、
意図せずアサーションに失敗してしまう問題があるため、リモートの
攻撃者により、巧妙に細工された AV1 ファイルを介して、サービス拒否
攻撃 (クラッシュの発生) を可能とする脆弱性が存在します。
(CVE-2026-52718)
- GStreamer の gst-plugins-bad に含まれる VA JPEG decoder には、
メモリ領域の範囲外読み取りの問題があるため、リモートの攻撃者により、
巧妙に細工された JPEG ファイルを介して、情報の漏洩、およびサービス
拒否攻撃 (クラッシュの発生) を可能とする脆弱性が存在します。
(CVE-2026-52719)
- GStreamer の librfb には、ヒープベースのバッファオーバーフロー
の問題があるため、リモートの攻撃者により、任意のコードの実行、
およびサービス拒否攻撃 (DoS) を可能とする脆弱性が存在します。
(CVE-2026-52720)
- GStreamer の VMnc デコーダには、整数オーバーフローの問題が
あるため、リモートの攻撃者により、巧妙に細工された VMnc ファイル
を介して、情報の漏洩、およびサービス拒否攻撃 (クラッシュの発生) を
可能とする脆弱性が存在します。(CVE-2026-52722)
解決策:
パッケージをアップデートしてください。
CVE:
CVE-2026-52718
A denial of service vulnerability was found in GStreamer's AV1 codec parser in gst-plugins-bad. The gst_av1_parser_parse_tile_list_obu() function passes a byte count to a bit-reader API that expects a bit count, causing parser desynchronization. A remote attacker could trick a user into opening a specially crafted AV1 media file, triggering an assertion abort and causing the application to crash.
A denial of service vulnerability was found in GStreamer's AV1 codec parser in gst-plugins-bad. The gst_av1_parser_parse_tile_list_obu() function passes a byte count to a bit-reader API that expects a bit count, causing parser desynchronization. A remote attacker could trick a user into opening a specially crafted AV1 media file, triggering an assertion abort and causing the application to crash.
CVE-2026-52719
An out-of-bounds read vulnerability was found in the VA JPEG decoder in GStreamer's gst-plugins-bad. The JPEG parser reads a segment length value from the bitstream without validating it against available data. A remote attacker could trick a user into opening a specially crafted JPEG file, causing downstream parsing to read beyond the provided input buffer, leading to a crash or potential information disclosure.
An out-of-bounds read vulnerability was found in the VA JPEG decoder in GStreamer's gst-plugins-bad. The JPEG parser reads a segment length value from the bitstream without validating it against available data. A remote attacker could trick a user into opening a specially crafted JPEG file, causing downstream parsing to read beyond the provided input buffer, leading to a crash or potential information disclosure.
CVE-2026-52720
A heap buffer overflow vulnerability was found in GStreamer's librfb (RFB/VNC client). The rectangle bounds check incorrectly validates area rather than individual dimensions, allowing a malicious VNC server to send a rectangle that extends beyond the framebuffer. A remote attacker could set up a malicious VNC server and trick a user into connecting, resulting in an out-of-bounds heap write that could lead to code execution or a crash.
A heap buffer overflow vulnerability was found in GStreamer's librfb (RFB/VNC client). The rectangle bounds check incorrectly validates area rather than individual dimensions, allowing a malicious VNC server to send a rectangle that extends beyond the framebuffer. A remote attacker could set up a malicious VNC server and trick a user into connecting, resulting in an out-of-bounds heap write that could lead to code execution or a crash.
CVE-2026-52722
A signed integer overflow vulnerability was found in GStreamer's VMnc decoder. A crafted VMnc stream with large cursor dimensions can overflow signed integer payload-size arithmetic, bypassing a length check and leading to out-of-bounds reads. A remote attacker could trick a user into opening a specially crafted VMnc file, potentially causing a crash or information disclosure.
A signed integer overflow vulnerability was found in GStreamer's VMnc decoder. A crafted VMnc stream with large cursor dimensions can overflow signed integer payload-size arithmetic, bypassing a length check and leading to out-of-bounds reads. A remote attacker could trick a user into opening a specially crafted VMnc file, potentially causing a crash or information disclosure.
追加情報:
N/A
ダウンロード:
SRPMS
- gstreamer1-plugins-bad-free-1.22.12-7.el9_8.1.src.rpm
MD5: c9807247edbb670f486a6c17dd0e0b39
SHA-256: e78c67c876fd88c4d14eae892d2abdb7b60b68929dfd08fb10721c5a2d9e7b6e
Size: 5.33 MB
Asianux Server 9 for x86_64
- gstreamer1-plugins-bad-free-1.22.12-7.el9_8.1.x86_64.rpm
MD5: c0df683f46bcfa7951970455e7c7bebe
SHA-256: 98618a13621151dbef951770109fd4a0eb23fde56e4cbf9436593770d03500c8
Size: 2.48 MB - gstreamer1-plugins-bad-free-devel-1.22.12-7.el9_8.1.x86_64.rpm
MD5: e5dff1f7aa152cbc1e2b28fcd2f197f6
SHA-256: f798df614494be84feb750a048814c16d2cb0c96babf4e51d5eb200c2b5a491e
Size: 314.58 kB - gstreamer1-plugins-bad-free-libs-1.22.12-7.el9_8.1.x86_64.rpm
MD5: ff4f2a6b746313d89937fb98d672ec9a
SHA-256: 86e08d0d229c49e168077ea53ff35b272417833efa89ab316140a32512f6f5a3
Size: 766.22 kB