Back to Security Advisories
High 2026-07-29

Gstreamer1-Plugins-Bad-Free Security Update — AlmaLinux 8 (ALSA-2026:47731)

AlmaLinux 8

GStreamer is a streaming media framework based on graphs of filters which operate on media data. The gstreamer1-plugins-bad-free package contains a collection of plug-ins for GStreamer. Security Fix(es): * gstreamer: gstreamer: rfbsrc/librfb Hextile heap out-of-bounds write with 16bpp framebuffer (CVE-2026-5…

GStreamer is a streaming media framework based on graphs of filters which operate on media data. The gstreamer1-plugins-bad-free package contains a collection of plug-ins for GStreamer.

Security Fix(es):

* gstreamer: gstreamer: rfbsrc/librfb Hextile heap out-of-bounds write with 16bpp framebuffer (CVE-2026-5…

Type:
security

Severity:
important

Release date:
2026-07-29

Description:
GStreamer is a streaming media framework based on graphs of filters which operate on media data. The gstreamer1-plugins-bad-free package contains a collection of plug-ins for GStreamer.

Security Fix(es):

* gstreamer: gstreamer: rfbsrc/librfb Hextile heap out-of-bounds write with 16bpp framebuffer (CVE-2026-59691)
* gstreamer: gstreamer: DTLS certificate Subject DN stack buffer overflow in openssl_verify_callback (CVE-2026-59692)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Updated packages listed below:

Architecture Package Checksum
aarch64 gstreamer1-plugins-bad-free-devel-1.16.1-9.el8_10.1.aarch64.rpm 3c644c3cd543215f0c5ea0ca87010e1b73997fc4ee6da416a0a2dfd25dc20f68
aarch64 gstreamer1-plugins-bad-free-1.16.1-9.el8_10.1.aarch64.rpm 3e472548fa2378f4e4c6e88252cc482341e8242881ee983f4c64fcf787bace9c
i686 gstreamer1-plugins-bad-free-devel-1.16.1-9.el8_10.1.i686.rpm bdcb236fdf431d90748b0dba0e5c85fe9a7cc90a8208227db0166450dd1a38ff
i686 gstreamer1-plugins-bad-free-1.16.1-9.el8_10.1.i686.rpm d21bb1a492d8e52ef70e3048e961e13ffa173bb26c23f3318068c5af9a3e6820
ppc64le gstreamer1-plugins-bad-free-1.16.1-9.el8_10.1.ppc64le.rpm 98e02c32fc92ccf765af9bf031dc4b9c3da9fd8f4dca02220782fed567fc25ca
ppc64le gstreamer1-plugins-bad-free-devel-1.16.1-9.el8_10.1.ppc64le.rpm a6320f8ddadba0f116b2ed5b4f9257215a07913d0d56203b327eb856b981f09b
s390x gstreamer1-plugins-bad-free-1.16.1-9.el8_10.1.s390x.rpm 397a2a5760518a0c5ae06c7ee0f0e7eb9406e510a85e3715f6a39769a4cdb2d8
s390x gstreamer1-plugins-bad-free-devel-1.16.1-9.el8_10.1.s390x.rpm a9f7cd1e972a7ebabf71ba5152d788496224c0f838f0de0193e38f5af884cab9
x86_64 gstreamer1-plugins-bad-free-devel-1.16.1-9.el8_10.1.x86_64.rpm 9a45a21a606429f59772ec4955b21e219484851db4bb706c28dac8294392f307
x86_64 gstreamer1-plugins-bad-free-1.16.1-9.el8_10.1.x86_64.rpm b1b6a046b59bee12af5bf509c49090b5bfc81c5a2cd1be9b554c5e10943068ad

Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.

How to Apply the Fix

Update the affected packages on your server to the patched release, then restart the relevant services.

sudo dnf update
More Information

Check your system for vulnerabilities

Wählen Sie Ihr Produkt und Betriebssystem, um die passenden Fix-Befehle zu sehen.

Check Your System