GStreamer streaming media framework base plugins
Go to file
RHEL Packaging Agent e3fa46713d Fix CVE-2026-18297: opusdec channel position overflow
Backport upstream fix (GStreamer MR !12044) for
CVE-2026-18297 to gstreamer1-plugins-base-1.16.1.

The patch adds a guard in gst_opus_dec_negotiate() to avoid
using channel positions when there are more than 64 channels,
which is unsupported. The patch paths were adjusted from the
upstream monorepo layout to the standalone 1.16.1 source tree.

CVE: CVE-2026-18297
Upstream patches:
 - https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12044.patch
Resolves: RHEL-246576

This commit was backported by Ymir, a Red Hat Enterprise Linux software maintenance AI agent.

Assisted-by: Ymir
2026-08-25 07:13:42 +00:00
.gitignore Import rpm: c8s 2023-02-27 13:29:35 -05:00
0001-missing-plugins-Remove-the-mpegaudioversion-field.patch Fixes for CVE-2024-47538, CVE-2024-47607, CVE-2024-47615 2024-12-16 16:02:11 +01:00
0001-riff-Correctly-check-that-enough-RGB-palette-data-is.patch Add patch for CVE-2026-2921 2026-03-31 12:57:07 +02:00
0002-video-disable-ORC_RESTRICT.patch Fixes for CVE-2024-47538, CVE-2024-47607, CVE-2024-47615 2024-12-16 16:02:11 +01:00
0003-subparse-Look-for-the-closing-of-a-tag-after-the-ope.patch Fixes for CVE-2024-47538, CVE-2024-47607, CVE-2024-47615 2024-12-16 16:02:11 +01:00
0004-subparse-Skip-after-the-end-of-a-valid-closing-tag-i.patch Fixes for CVE-2024-47538, CVE-2024-47607, CVE-2024-47615 2024-12-16 16:02:11 +01:00
0005-exiftag-Prevent-integer-overflows-and-out-of-bounds-.patch Fixes for CVE-2024-47538, CVE-2024-47607, CVE-2024-47615 2024-12-16 16:02:11 +01:00
0006-opusdec-Set-at-most-64-channels-to-NONE-position.patch Fixes for CVE-2024-47538, CVE-2024-47607, CVE-2024-47615 2024-12-16 16:02:11 +01:00
0007-vorbis_parse-check-writes-to-GstOggStream.vorbis_mod.patch Fixes for CVE-2024-47538, CVE-2024-47607, CVE-2024-47615 2024-12-16 16:02:11 +01:00
0008-vorbisdec-Set-at-most-64-channels-to-NONE-position.patch Fixes for CVE-2024-47538, CVE-2024-47607, CVE-2024-47615 2024-12-16 16:02:11 +01:00
gating.yaml Bring gating.yaml over from Brew dist-git 2023-03-10 10:43:12 -08:00
gstreamer1-plugins-base-1.16.1-CVE-2026-18297.patch Fix CVE-2026-18297: opusdec channel position overflow 2026-08-25 07:13:42 +00:00
gstreamer1-plugins-base.spec Fix CVE-2026-18297: opusdec channel position overflow 2026-08-25 07:13:42 +00:00
sources Auto sync2gitlab import of gstreamer1-plugins-base-1.16.1-2.el8.src.rpm 2022-05-26 09:17:06 -04:00