gstreamer1-plugins-ugly-free-1.22.12-6.el9_8.1
エラータID: AXSA:2026-1481:01
リリース日:
2026/08/07 Friday - 15:34
題名:
gstreamer1-plugins-ugly-free-1.22.12-6.el9_8.1
影響のあるチャネル:
MIRACLE LINUX 9 for x86_64
Severity:
Moderate
Description:
以下項目について対処しました。
[Security Fix]
- GStreamer には、メモリ領域の範囲外読み取りの問題があるため、
リモートの攻撃者により、情報の漏洩、およびサービス拒否攻撃を
可能とする脆弱性が存在します。(CVE-2026-53703)
- GStreamer には、メモリ領域の範囲外読み取りの問題があるため、
リモートの攻撃者により、巧妙に細工された RealMedia ファイルを
介して、情報の漏洩、およびサービス拒否攻撃を可能とする脆弱性が
存在します。(CVE-2026-53704)
解決策:
パッケージをアップデートしてください。
CVE:
CVE-2026-53703
A vulnerability was found in the GStreamer RealMedia demuxer (gst-plugins-ugly). When processing a RealMedia (.rm) file, the demuxer parses MDPR (media properties) chunks to configure audio streams. For audio stream header versions 4 and 5, the parser reads fields such as codec type, packet size, sample rate, channel count, and extra codec data length from fixed offsets within the chunk without first checking that the chunk contains enough data. If a malicious file provides an MDPR chunk that is too small to contain a complete audio stream header, the parser reads beyond the end of the buffer. This can cause the application to crash. In some cases, bytes read past the buffer boundary may be incorporated into stream metadata, which could result in limited information disclosure.
A vulnerability was found in the GStreamer RealMedia demuxer (gst-plugins-ugly). When processing a RealMedia (.rm) file, the demuxer parses MDPR (media properties) chunks to configure audio streams. For audio stream header versions 4 and 5, the parser reads fields such as codec type, packet size, sample rate, channel count, and extra codec data length from fixed offsets within the chunk without first checking that the chunk contains enough data. If a malicious file provides an MDPR chunk that is too small to contain a complete audio stream header, the parser reads beyond the end of the buffer. This can cause the application to crash. In some cases, bytes read past the buffer boundary may be incorporated into stream metadata, which could result in limited information disclosure.
CVE-2026-53704
A flaw was found in GStreamer's RealMedia demuxer in the gst-plugins-ugly package. When processing a RealMedia file containing a specially crafted FILEINFO metadata section, the demuxer parses variable-name and variable-value pairs using re_skip_pascal_string() without validating that offsets remain within the mapped buffer. Additionally, the element count controlling the parsing loop is read from attacker-controlled data without validation, which can cause an infinite loop. A crafted RealMedia file can cause the application to crash, hang, or potentially read limited adjacent memory contents.
A flaw was found in GStreamer's RealMedia demuxer in the gst-plugins-ugly package. When processing a RealMedia file containing a specially crafted FILEINFO metadata section, the demuxer parses variable-name and variable-value pairs using re_skip_pascal_string() without validating that offsets remain within the mapped buffer. Additionally, the element count controlling the parsing loop is read from attacker-controlled data without validation, which can cause an infinite loop. A crafted RealMedia file can cause the application to crash, hang, or potentially read limited adjacent memory contents.
追加情報:
N/A
ダウンロード:
SRPMS
- gstreamer1-plugins-ugly-free-1.22.12-6.el9_8.1.src.rpm
MD5: 35d92c6cadec1cad210db0b2fd6defec
SHA-256: 58ec3e722610226d25b8d859ecb2d62f923a5cfd9b919fbe4679aab155e00007
Size: 273.52 kB
Asianux Server 9 for x86_64
- gstreamer1-plugins-ugly-free-1.22.12-6.el9_8.1.x86_64.rpm
MD5: c3d519bf2d6c04d39ffdee84789564f9
SHA-256: 396fa9fee964af2f61d751b0509700c6690e0e44b6b8c72a3afcbf729469c33f
Size: 279.50 kB