Back to Security Advisories
High 2026-08-06

Gstreamer1-Plugins-Bad-Free Security Update — AlmaLinux 9 (ALSA-2026:47179)

AlmaLinux 9

GStreamer is a streaming media framework based on graphs of filters which operate on media data. The gstreamer1-plugins-bad-free package contains a collection of plug-ins for GStreamer. Security Fix(es): * gstreamer: gstreamer: rfbsrc/librfb Hextile heap out-of-bounds write with 16bpp framebuffer (CVE-2026-5…

GStreamer is a streaming media framework based on graphs of filters which operate on media data. The gstreamer1-plugins-bad-free package contains a collection of plug-ins for GStreamer.

Security Fix(es):

* gstreamer: gstreamer: rfbsrc/librfb Hextile heap out-of-bounds write with 16bpp framebuffer (CVE-2026-5…

Type:
security

Severity:
important

Release date:
2026-08-06

Description:
GStreamer is a streaming media framework based on graphs of filters which operate on media data. The gstreamer1-plugins-bad-free package contains a collection of plug-ins for GStreamer.

Security Fix(es):

* gstreamer: gstreamer: rfbsrc/librfb Hextile heap out-of-bounds write with 16bpp framebuffer (CVE-2026-59691)
* gstreamer: gstreamer: DTLS certificate Subject DN stack buffer overflow in openssl_verify_callback (CVE-2026-59692)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Updated packages listed below:

Architecture Package Checksum
aarch64 gstreamer1-plugins-bad-free-1.22.12-7.el9_8.3.aarch64.rpm 45b33639e24c53c3b2b9d476826c974cc24e26de83946bcda82aaa687978ea38
aarch64 gstreamer1-plugins-bad-free-libs-1.22.12-7.el9_8.3.aarch64.rpm 5b3e64779ea4f80ea8913fb14cd3c5bd2b91371a472dcabc0956e28cd92efaf4
aarch64 gstreamer1-plugins-bad-free-devel-1.22.12-7.el9_8.3.aarch64.rpm cf7db9af80a55d1d8bab0535c1533e98fd41f241c3b566282c15b57068b2b8fc
i686 gstreamer1-plugins-bad-free-libs-1.22.12-7.el9_8.3.i686.rpm 10461af212f753de26ca66dfc35f04f8b6c2f2c98038a4d61f4ff20a93508c73
i686 gstreamer1-plugins-bad-free-devel-1.22.12-7.el9_8.3.i686.rpm 4348f0a0fd22f8fffa8486c724ed3d68fe7c254b149514355f069824f80a9ee2
i686 gstreamer1-plugins-bad-free-1.22.12-7.el9_8.3.i686.rpm c9d80cb2a52bec5bd671cd0553b907622a56749489c0b28b60580fd34889bea9
ppc64le gstreamer1-plugins-bad-free-libs-1.22.12-7.el9_8.3.ppc64le.rpm 4b8decd65927b4a9803fd936322dccaf25266d7f6e66a3dec98dfee7a278b29c
ppc64le gstreamer1-plugins-bad-free-1.22.12-7.el9_8.3.ppc64le.rpm 585c9019760e0bd04cf60c6f0c3defa2b84dd6efbfd3dd2a51e3917968a8cb0e
ppc64le gstreamer1-plugins-bad-free-devel-1.22.12-7.el9_8.3.ppc64le.rpm 5f25f073d831262d2b896947ba951e1218657068715380d25d7021760ca744e3
s390x gstreamer1-plugins-bad-free-devel-1.22.12-7.el9_8.3.s390x.rpm 08e86c8aad6b2fb95a93cd4f7b173ef0ba3d6a403663f895eba830e4798851b4
s390x gstreamer1-plugins-bad-free-1.22.12-7.el9_8.3.s390x.rpm 5e7c573a27312fd5f0ab4746a43d23e868be1c5a9bb47d31a1fbd8ad9c62c746
s390x gstreamer1-plugins-bad-free-libs-1.22.12-7.el9_8.3.s390x.rpm ede4180df46f9e1866ed44efbf11a1f10d0e361063b12801849f018fd440a96f
x86_64 gstreamer1-plugins-bad-free-1.22.12-7.el9_8.3.x86_64.rpm 4aac33f087fa8159f793d550877ebaeefb79ec65d8c963e77bb5a81d90c89025
x86_64 gstreamer1-plugins-bad-free-devel-1.22.12-7.el9_8.3.x86_64.rpm 66e634e424fdc9bc8e7538f2c1c0a2e4c46f87311e87daf242ba46bdfc5b3dae
x86_64 gstreamer1-plugins-bad-free-libs-1.22.12-7.el9_8.3.x86_64.rpm 6c3cdd85c5e94807d8d415c345031ab62db91ee70102656cf49794c1d44d8712

Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.

How to Apply the Fix

Update the affected packages on your server to the patched release, then restart the relevant services.

sudo dnf update
More Information

Check your system for vulnerabilities

Select your product and operating system to see the exact fix commands that apply to you.

Check Your System