diff --git a/gstreamer1-plugins-good-1.22.12-CVE-2026-18299.patch b/gstreamer1-plugins-good-1.22.12-CVE-2026-18299.patch new file mode 100644 index 0000000..d9e9c9d --- /dev/null +++ b/gstreamer1-plugins-good-1.22.12-CVE-2026-18299.patch @@ -0,0 +1,111 @@ +From 3f69d9930a2d0ef42a057ebc30ba8f4a18550192 Mon Sep 17 00:00:00 2001 +From: =?UTF-8?q?Sebastian=20Dr=C3=B6ge?= +Date: Fri, 19 Jun 2026 12:50:32 +0300 +Subject: [PATCH 1/3] rtpsbcdepay: Check for available data in the adapter + before getting data + +Consider empty packets with the last flag as bad packets. + +Also reset buffers to NULL after giving away ownership of them to avoid +returning an already freed buffer. + +Fixes https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5119 + +Part-of: +--- + .../gst-plugins-good/gst/rtp/gstrtpsbcdepay.c | 29 ++++++++++++------- + 1 file changed, 18 insertions(+), 11 deletions(-) + +diff --git a/subprojects/gst-plugins-good/gst/rtp/gstrtpsbcdepay.c b/subprojects/gst-plugins-good/gst/rtp/gstrtpsbcdepay.c +index f5dec8b787..e2ff02b520 100644 +--- a/subprojects/gst-plugins-good/gst/rtp/gstrtpsbcdepay.c ++++ b/subprojects/gst-plugins-good/gst/rtp/gstrtpsbcdepay.c +@@ -327,19 +327,26 @@ gst_rtp_sbc_depay_process (GstRTPBaseDepayload * base, GstRTPBuffer * rtp) + } + + gst_adapter_push (depay->adapter, data); ++ data = NULL; + + if (last) { +- gint framelen, samples; +- guint8 header[4]; +- +- data = gst_adapter_take_buffer (depay->adapter, +- gst_adapter_available (depay->adapter)); +- gst_rtp_drop_non_audio_meta (depay, data); +- +- if (gst_buffer_extract (data, 0, &header, 4) != 4 || +- gst_rtp_sbc_depay_get_params (depay, header, +- payload_len, &framelen, &samples) < 0) { +- gst_buffer_unref (data); ++ if (gst_adapter_available (depay->adapter)) { ++ gint framelen, samples; ++ guint8 header[4]; ++ ++ data = gst_adapter_take_buffer (depay->adapter, ++ gst_adapter_available (depay->adapter)); ++ gst_rtp_drop_non_audio_meta (depay, data); ++ ++ if (gst_buffer_extract (data, 0, &header, 4) != 4 || ++ gst_rtp_sbc_depay_get_params (depay, header, ++ payload_len, &framelen, &samples) < 0) { ++ gst_buffer_unref (data); ++ data = NULL; ++ goto bad_packet; ++ } ++ } else { ++ data = NULL; + goto bad_packet; + } + } else { + +From c2604bd1876aa527c747b539143f87aa75215e1e Mon Sep 17 00:00:00 2001 +From: =?UTF-8?q?Sebastian=20Dr=C3=B6ge?= +Date: Fri, 19 Jun 2026 12:55:34 +0300 +Subject: [PATCH 2/3] rtpsbcdepay: Check that enough data is available for the + payload header + +Part-of: +--- + subprojects/gst-plugins-good/gst/rtp/gstrtpsbcdepay.c | 2 ++ + 1 file changed, 2 insertions(+) + +diff --git a/subprojects/gst-plugins-good/gst/rtp/gstrtpsbcdepay.c b/subprojects/gst-plugins-good/gst/rtp/gstrtpsbcdepay.c +index e2ff02b520..f195b883eb 100644 +--- a/subprojects/gst-plugins-good/gst/rtp/gstrtpsbcdepay.c ++++ b/subprojects/gst-plugins-good/gst/rtp/gstrtpsbcdepay.c +@@ -300,6 +300,8 @@ gst_rtp_sbc_depay_process (GstRTPBaseDepayload * base, GstRTPBuffer * rtp) + + payload = gst_rtp_buffer_get_payload (rtp); + payload_len = gst_rtp_buffer_get_payload_len (rtp); ++ if (payload_len < 1) ++ goto bad_packet; + + fragment = payload[0] & 0x80; + start = payload[0] & 0x40; + +From 8a6585f373c32633fcc751360d7cde6b1d5348d0 Mon Sep 17 00:00:00 2001 +From: =?UTF-8?q?Sebastian=20Dr=C3=B6ge?= +Date: Fri, 19 Jun 2026 13:00:27 +0300 +Subject: [PATCH 3/3] rtpsbcdepay: Remove wrong variable shadowing + +`samples` is expected to be set in the outer scope at a later time. + +Part-of: +--- + subprojects/gst-plugins-good/gst/rtp/gstrtpsbcdepay.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/subprojects/gst-plugins-good/gst/rtp/gstrtpsbcdepay.c b/subprojects/gst-plugins-good/gst/rtp/gstrtpsbcdepay.c +index f195b883eb..0dc9172c8c 100644 +--- a/subprojects/gst-plugins-good/gst/rtp/gstrtpsbcdepay.c ++++ b/subprojects/gst-plugins-good/gst/rtp/gstrtpsbcdepay.c +@@ -333,7 +333,7 @@ gst_rtp_sbc_depay_process (GstRTPBaseDepayload * base, GstRTPBuffer * rtp) + + if (last) { + if (gst_adapter_available (depay->adapter)) { +- gint framelen, samples; ++ gint framelen; + guint8 header[4]; + + data = gst_adapter_take_buffer (depay->adapter, diff --git a/gstreamer1-plugins-good.spec b/gstreamer1-plugins-good.spec index 143ac20..5f72066 100644 --- a/gstreamer1-plugins-good.spec +++ b/gstreamer1-plugins-good.spec @@ -28,7 +28,7 @@ Name: gstreamer1-plugins-good Version: 1.22.12 -Release: 13%{?dist} +Release: 14%{?dist} Summary: GStreamer plugins with good code and licensing License: CC0-1.0 AND GPL-2.0-only AND LGPL-2.0-only AND LGPL-2.0-or-later AND LGPL-2.1-only AND LGPL-2.1-or-later AND xlock AND MIT AND BSD-3-Clause AND CC-BY-3.0 @@ -95,6 +95,9 @@ Patch0034: gstreamer1-plugins-good-1.22.12-CVE-2026-18296.patch # https://issues.redhat.com/browse/RHEL-246559 # https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12043 Patch0035: gstreamer1-plugins-good-1.22.12-CVE-2026-18298.patch +# https://issues.redhat.com/browse/RHEL-246616 +# https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12042 +Patch0036: gstreamer1-plugins-good-1.22.12-CVE-2026-18299.patch BuildRequires: meson >= 0.48.0 BuildRequires: gcc @@ -289,6 +292,7 @@ to be installed. %patch -P 0033 -p3 %patch -P 0034 -p3 %patch -P 0035 -p3 +%patch -P 0036 -p3 %build %meson \ @@ -439,6 +443,9 @@ find $RPM_BUILD_ROOT -name '*.la' -exec rm -fv {} ';' %changelog +* Tue Aug 25 2026 RHEL Packaging Agent - 1.22.12-14 +- Fix use-after-free in rtpsbcdepay (CVE-2026-18299) + * Tue Aug 25 2026 RHEL Packaging Agent - 1.22.12-13 - Fix gdkpixbufdec format and resolution change handling (CVE-2026-18298)