Description:
GStreamer is a streaming media framework based on graphs of filters which operate on media data. The gstreamer1-plugins-base packages contain a collection of well-maintained base plug-ins.
Security Fix(es):
* gstreamer: GStreamer: Arbitrary code execution via OGG file parsing buffer overflow (CVE-2026-18297)
* gstreamer1-plugins-base: gstreamer: NULL/invalid-pointer dereference in gst_rtsp_message_parse_auth_credentials() when parsing a crafted Digest Authorization/WWW-Authenticate header (CVE-2026-85150)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
| Architecture |
Package |
Checksum |
| i686 |
gstreamer1-plugins-base-1.22.12-8.el9_8.2.i686.rpm |
8c376c29ad743aa24d8d6326847cfd1b4432a68b7fd1df0b075ba83d79385900 |
| ppc64le |
gstreamer1-plugins-base-1.22.12-8.el9_8.2.ppc64le.rpm |
ce9b831b5cd954a8abf8ac4db47ef252b96550d7291a04a44067f27e5911d8e7 |
| x86_64 |
gstreamer1-plugins-base-1.22.12-8.el9_8.2.x86_64.rpm |
79a8842996de27c8aac88997744ab6cf0400f3e43b1ab8bf9a1bcc33b7a3898f |