Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:70264 - Security Advisory
Issued:
2026-09-22
Updated:
2026-09-22

RHSA-2026:70264 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: gstreamer1-plugins-good security update

Type/Severity

Security Advisory: Moderate

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for gstreamer1-plugins-good is now available for Red Hat Enterprise Linux 7 Extended Lifecycle Support.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

GStreamer is a streaming media framework based on graphs of filters which operate on media data. The gstreamer1-plugins-good packages contain a collection of well-supported plug-ins of good quality and under the LGPL license.

Security Fix(es):

  • gst-plugins-good: gst-plugins-good: unbounded memory growth in rtph264depay and rtph265depay RTP depayloaders (CVE-2026-18649)
  • gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux FUJIFILM strd parsing leading to out-of-bounds read/write (CVE-2026-73433)
  • gstreamer1-plugins-good: gstreamer: out-of-bounds read in avidemux vprp video field descriptor parsing (CVE-2026-73434)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server - Extended Life Cycle Support 7 x86_64
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 7 s390x
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian 7 ppc64
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian 7 ppc64le

Fixes

  • BZ - 2510614 - CVE-2026-18649 gst-plugins-good: gst-plugins-good: unbounded memory growth in rtph264depay and rtph265depay RTP depayloaders
  • BZ - 2514801 - CVE-2026-73433 gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux FUJIFILM strd parsing leading to out-of-bounds read/write
  • BZ - 2514807 - CVE-2026-73434 gstreamer1-plugins-good: gstreamer: out-of-bounds read in avidemux vprp video field descriptor parsing

CVEs

  • CVE-2026-18649
  • CVE-2026-73433
  • CVE-2026-73434

References

  • https://access.redhat.com/security/updates/classification/#moderate
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server - Extended Life Cycle Support 7

SRPM
gstreamer1-plugins-good-1.10.4-4.el7_9.3.src.rpm SHA-256: e24e0632b529fee0a4e5a27678fa12e998d9a08e660e118a8a57bcbd81d91ef1
x86_64
gstreamer1-plugins-good-1.10.4-4.el7_9.3.i686.rpm SHA-256: 9079d5c179f02342f13c7e1a0d01d5e7b8620b9edddb30066d8f9e6f8eeba76e
gstreamer1-plugins-good-1.10.4-4.el7_9.3.x86_64.rpm SHA-256: b24cc390007b1caba8f526eb88bc79dde155d6c24d1cfea7b2e21bb974f14ad4
gstreamer1-plugins-good-debuginfo-1.10.4-4.el7_9.3.i686.rpm SHA-256: ad7c6f587a35c0f6f242e198a3763b5948a486149301a096a6b6ef3ed8d5b89e
gstreamer1-plugins-good-debuginfo-1.10.4-4.el7_9.3.x86_64.rpm SHA-256: eefc25a163f4fe98904b991d38e21c93564f9d7b719b284c3cae7501e3c85e28

Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 7

SRPM
gstreamer1-plugins-good-1.10.4-4.el7_9.3.src.rpm SHA-256: e24e0632b529fee0a4e5a27678fa12e998d9a08e660e118a8a57bcbd81d91ef1
s390x
gstreamer1-plugins-good-1.10.4-4.el7_9.3.s390.rpm SHA-256: df3aafe14bda33efcd83f94aa64922f389739028fa9891327eb94da9cbc3e5ae
gstreamer1-plugins-good-1.10.4-4.el7_9.3.s390x.rpm SHA-256: 480f3a2baf2342a229c9cad5c74a168422da6e174d5a23b57e92a0b52ca3c2d0
gstreamer1-plugins-good-debuginfo-1.10.4-4.el7_9.3.s390.rpm SHA-256: 4114876408ee482fbb32f74c4a6bba70621ba455bd1dbd279a60adc647f56f2a
gstreamer1-plugins-good-debuginfo-1.10.4-4.el7_9.3.s390x.rpm SHA-256: 7041c89c945ee9307528d1acdefb008da4f51b93c3c84bdebb5a996d834ddf84

Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian 7

SRPM
gstreamer1-plugins-good-1.10.4-4.el7_9.3.src.rpm SHA-256: e24e0632b529fee0a4e5a27678fa12e998d9a08e660e118a8a57bcbd81d91ef1
ppc64
gstreamer1-plugins-good-1.10.4-4.el7_9.3.ppc.rpm SHA-256: 15c1e5d429619916cb21b26ef30792298ae7b440702291d5c4b7f363361fe69c
gstreamer1-plugins-good-1.10.4-4.el7_9.3.ppc64.rpm SHA-256: 90e30486e12f2670fb0a51f3c2189dcdeb133330061455ce92b20efebc57a010
gstreamer1-plugins-good-debuginfo-1.10.4-4.el7_9.3.ppc.rpm SHA-256: 5321cb6b7199d4a74d04b49c5f24f4b46e9b053714c04f7d332d75fd35453dc7
gstreamer1-plugins-good-debuginfo-1.10.4-4.el7_9.3.ppc64.rpm SHA-256: e6a4b149eb2ce79ab19f769d2170abc649b8a079bd46f5f74569784716e438b5

Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian 7

SRPM
gstreamer1-plugins-good-1.10.4-4.el7_9.3.src.rpm SHA-256: e24e0632b529fee0a4e5a27678fa12e998d9a08e660e118a8a57bcbd81d91ef1
ppc64le
gstreamer1-plugins-good-1.10.4-4.el7_9.3.ppc64le.rpm SHA-256: 08b23b3c3a15fd5ea0629d1b14410d4a30e78afa6b9fed81d5064b91997ac2b6
gstreamer1-plugins-good-debuginfo-1.10.4-4.el7_9.3.ppc64le.rpm SHA-256: 666943efbd3ab43fa657c89e305d83b030cbf561b0b72884a94bf0dacbe27fb2

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility