[ALSA-2026:55435] Important: gstreamer1-plugins-ugly-free security update
Type:
security
Severity:
important
Release date:
2026-08-18
Description:
GStreamer is a streaming media framework, based on graphs of elements which operate on media data. This package contains plug-ins whose license is not fully compatible with LGPL. Security Fix(es): * gstreamer: gstreamer1-plugins-ugly-free: gstreamer: integer overflow/underflow in asfdemux bounds checks leading to out-of-bounds read (CVE-2026-19389) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 gstreamer1-plugins-ugly-free-1.26.7-2.el10_2.2.aarch64.rpm 06bee9913332130808f3d673c597a625b92d6def3b5bbc99f71781fcc3dc88dc
ppc64le gstreamer1-plugins-ugly-free-1.26.7-2.el10_2.2.ppc64le.rpm 0d6d4b356064775870649c2f76c220f39d996fd55f374b86e50213f0d99a79dd
x86_64 gstreamer1-plugins-ugly-free-1.26.7-2.el10_2.2.x86_64.rpm 87ca66be1b5fbf7903a391342539e1e4916cec746b044f56d715a792533b066e
x86_64_v2 gstreamer1-plugins-ugly-free-1.26.7-2.el10_2.2.x86_64_v2.rpm f1f3c129ff1616f85e7b241a3ed92b06e4c061c66e3a5a401e9b9558b05421d8
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.