Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:49517 - Security Advisory
Issued:
2026-08-03
Updated:
2026-08-03

RHSA-2026:49517 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: gstreamer-plugins-bad-free security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for gstreamer-plugins-bad-free is now available for Red Hat Enterprise Linux 7 Extended Lifecycle Support.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

GStreamer is a streaming media framework based on graphs of filters which operate on media data. The gstreamer-plugins-bad-free package contains a collection of plug-ins for GStreamer.

Security Fix(es):

  • gstreamer1-plugins-bad-free: GStreamer: Heap buffer overflow via crafted VNC server rectangle in librfb (CVE-2026-52720)
  • gstreamer1-plugins-bad-free: GStreamer: Signed integer overflow in VMnc decoder cursor payload handling (CVE-2026-52722)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server - Extended Life Cycle Support 7 x86_64
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 7 s390x
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian 7 ppc64
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian 7 ppc64le

Fixes

  • BZ - 2486731 - CVE-2026-52720 gstreamer1-plugins-bad-free: GStreamer: Heap buffer overflow via crafted VNC server rectangle in librfb
  • BZ - 2486733 - CVE-2026-52722 gstreamer1-plugins-bad-free: GStreamer: Signed integer overflow in VMnc decoder cursor payload handling

CVEs

  • CVE-2026-52720
  • CVE-2026-52722

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server - Extended Life Cycle Support 7

SRPM
gstreamer-plugins-bad-free-0.10.23-25.el7_9.src.rpm SHA-256: 9d53af83d6083894be4046081baa225b446d352166c38cb7bd48a27fcaa775d6
x86_64
gstreamer-plugins-bad-free-0.10.23-25.el7_9.i686.rpm SHA-256: ca1132eb3c1a1967da913f17dc0c731627c968d03cc7565b2409cf77f66d6206
gstreamer-plugins-bad-free-0.10.23-25.el7_9.x86_64.rpm SHA-256: a8da88f519d2ea93e90e8e980a7cd4f49c08018d296e884d5648041face6aa0e
gstreamer-plugins-bad-free-debuginfo-0.10.23-25.el7_9.i686.rpm SHA-256: 95d9f21a6e1c518c36089f2cb84d0646681a90d6fa6c966ae4b23cabf1e24c5d
gstreamer-plugins-bad-free-debuginfo-0.10.23-25.el7_9.i686.rpm SHA-256: 95d9f21a6e1c518c36089f2cb84d0646681a90d6fa6c966ae4b23cabf1e24c5d
gstreamer-plugins-bad-free-debuginfo-0.10.23-25.el7_9.x86_64.rpm SHA-256: 40b435689676d2863f7199a62d514808207b21b1836d5a41e625d5524a9f3a2b
gstreamer-plugins-bad-free-debuginfo-0.10.23-25.el7_9.x86_64.rpm SHA-256: 40b435689676d2863f7199a62d514808207b21b1836d5a41e625d5524a9f3a2b
gstreamer-plugins-bad-free-devel-0.10.23-25.el7_9.i686.rpm SHA-256: 937f538772e47f38225f24012bb833b8e6e7782be5eabe017c3e2d8695b11286
gstreamer-plugins-bad-free-devel-0.10.23-25.el7_9.x86_64.rpm SHA-256: 16739add39ed6b06c14644bc7c0c9bc864e8a81869eb4ac12285a2461a0ac759
gstreamer-plugins-bad-free-devel-docs-0.10.23-25.el7_9.x86_64.rpm SHA-256: ec01b1f6bd31af762fb221774f79c81a0014c8c2717e2c70fd29de1ad28a98cd

Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 7

SRPM
gstreamer-plugins-bad-free-0.10.23-25.el7_9.src.rpm SHA-256: 9d53af83d6083894be4046081baa225b446d352166c38cb7bd48a27fcaa775d6
s390x
gstreamer-plugins-bad-free-0.10.23-25.el7_9.s390.rpm SHA-256: 40e1448f3bfaf49bd06eb39b02f5851720d8b806aaf1cb8bd8d8432413d252e7
gstreamer-plugins-bad-free-0.10.23-25.el7_9.s390x.rpm SHA-256: 1bb0e7d00d47684b4432ee2d2acf40dd93a904dd99cd2f075e0abd096e1f01ab
gstreamer-plugins-bad-free-debuginfo-0.10.23-25.el7_9.s390.rpm SHA-256: a41438b08d096fd98e22545508351ac345790bb21777f3080eaaa77222d6195a
gstreamer-plugins-bad-free-debuginfo-0.10.23-25.el7_9.s390.rpm SHA-256: a41438b08d096fd98e22545508351ac345790bb21777f3080eaaa77222d6195a
gstreamer-plugins-bad-free-debuginfo-0.10.23-25.el7_9.s390x.rpm SHA-256: 7e75997368c59e441dccd56da7627f8b0c1b6706128e3c549a2704992b3008a6
gstreamer-plugins-bad-free-debuginfo-0.10.23-25.el7_9.s390x.rpm SHA-256: 7e75997368c59e441dccd56da7627f8b0c1b6706128e3c549a2704992b3008a6
gstreamer-plugins-bad-free-devel-0.10.23-25.el7_9.s390.rpm SHA-256: 4ebccec7a78b16f42f35a1a93d94c5163911796af7ae4f4ac95d0c44b5f8433e
gstreamer-plugins-bad-free-devel-0.10.23-25.el7_9.s390x.rpm SHA-256: 08dbb1406c62ad2ac746b7f9c4d69cf2fc555046947e744a8d38a94106cbbad1
gstreamer-plugins-bad-free-devel-docs-0.10.23-25.el7_9.s390x.rpm SHA-256: cd6fa0e9189cd467401afe9426b255043f56b6f09780801d39d931e0944be7f7

Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian 7

SRPM
gstreamer-plugins-bad-free-0.10.23-25.el7_9.src.rpm SHA-256: 9d53af83d6083894be4046081baa225b446d352166c38cb7bd48a27fcaa775d6
ppc64
gstreamer-plugins-bad-free-0.10.23-25.el7_9.ppc.rpm SHA-256: af90dd9c2d3b5008d0c6e4bdfa20ff703fab740385441f7c34b04265c8e90a0d
gstreamer-plugins-bad-free-0.10.23-25.el7_9.ppc64.rpm SHA-256: d212939db43832e99f64a116f0355a1752e9a7b6283c99d2bee9415215ce5e6e
gstreamer-plugins-bad-free-debuginfo-0.10.23-25.el7_9.ppc.rpm SHA-256: 71331f009fc3e9e36b544424348cb9baeaa85767a53e8103ab908205e096f9b0
gstreamer-plugins-bad-free-debuginfo-0.10.23-25.el7_9.ppc.rpm SHA-256: 71331f009fc3e9e36b544424348cb9baeaa85767a53e8103ab908205e096f9b0
gstreamer-plugins-bad-free-debuginfo-0.10.23-25.el7_9.ppc64.rpm SHA-256: 22c1f9074d5141d392286d62ba67528abc4d72a548e54e096c65dd131d30ade7
gstreamer-plugins-bad-free-debuginfo-0.10.23-25.el7_9.ppc64.rpm SHA-256: 22c1f9074d5141d392286d62ba67528abc4d72a548e54e096c65dd131d30ade7
gstreamer-plugins-bad-free-devel-0.10.23-25.el7_9.ppc.rpm SHA-256: 5e8b51bcdfe5e42257736bd3e0954229f48fd1d8dd5ee941baac5145b475d2b6
gstreamer-plugins-bad-free-devel-0.10.23-25.el7_9.ppc64.rpm SHA-256: f62eae6ef75a4e2b7dbec78d8ed66a7d5270c386429dc05ca7355272dfcedb49
gstreamer-plugins-bad-free-devel-docs-0.10.23-25.el7_9.ppc64.rpm SHA-256: cf511c0e9de6897bfdaa099763ef0677ccf3d95b5e8f594df727eec976f400d7

Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian 7

SRPM
gstreamer-plugins-bad-free-0.10.23-25.el7_9.src.rpm SHA-256: 9d53af83d6083894be4046081baa225b446d352166c38cb7bd48a27fcaa775d6
ppc64le
gstreamer-plugins-bad-free-0.10.23-25.el7_9.ppc64le.rpm SHA-256: bf49a455fdbfd0e777b546f3f6615814bcab4de70deb238fd50b97156fcf0a88
gstreamer-plugins-bad-free-debuginfo-0.10.23-25.el7_9.ppc64le.rpm SHA-256: 3e1a9f609c766240b02b8ff71161590f0e3990b367a97086135b068bed8930be
gstreamer-plugins-bad-free-debuginfo-0.10.23-25.el7_9.ppc64le.rpm SHA-256: 3e1a9f609c766240b02b8ff71161590f0e3990b367a97086135b068bed8930be
gstreamer-plugins-bad-free-devel-0.10.23-25.el7_9.ppc64le.rpm SHA-256: 7525e42b6f3a81f1ef1b6d1234f9f2164112ee14b2e1355381368245862b558b
gstreamer-plugins-bad-free-devel-docs-0.10.23-25.el7_9.ppc64le.rpm SHA-256: f9a8a0fd795eb221dfd2aa7edf56cf5135fe4681ceafb50d693eff39efd8c20c

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility