GStreamer streaming media framework base plugins
Backport upstream fix (GStreamer MR !12044) for CVE-2026-18297 to gstreamer1-plugins-base-1.16.1. The patch adds a guard in gst_opus_dec_negotiate() to avoid using channel positions when there are more than 64 channels, which is unsupported. The patch paths were adjusted from the upstream monorepo layout to the standalone 1.16.1 source tree. CVE: CVE-2026-18297 Upstream patches: - https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12044.patch Resolves: RHEL-246576 This commit was backported by Ymir, a Red Hat Enterprise Linux software maintenance AI agent. Assisted-by: Ymir |
||
|---|---|---|
| .gitignore | ||
| 0001-missing-plugins-Remove-the-mpegaudioversion-field.patch | ||
| 0001-riff-Correctly-check-that-enough-RGB-palette-data-is.patch | ||
| 0002-video-disable-ORC_RESTRICT.patch | ||
| 0003-subparse-Look-for-the-closing-of-a-tag-after-the-ope.patch | ||
| 0004-subparse-Skip-after-the-end-of-a-valid-closing-tag-i.patch | ||
| 0005-exiftag-Prevent-integer-overflows-and-out-of-bounds-.patch | ||
| 0006-opusdec-Set-at-most-64-channels-to-NONE-position.patch | ||
| 0007-vorbis_parse-check-writes-to-GstOggStream.vorbis_mod.patch | ||
| 0008-vorbisdec-Set-at-most-64-channels-to-NONE-position.patch | ||
| gating.yaml | ||
| gstreamer1-plugins-base-1.16.1-CVE-2026-18297.patch | ||
| gstreamer1-plugins-base.spec | ||
| sources | ||