import CS git gstreamer1-plugins-good-1.16.1-7.el8_10.7

This commit is contained in:
AlmaLinux RelEng Bot 2026-08-24 16:48:28 -04:00
parent b045dfd302
commit 4fe84d93c4
4 changed files with 468 additions and 1 deletions

View File

@ -0,0 +1,259 @@
From d487603fa1f0eb7202a7e3f662eb7617da4969ef Mon Sep 17 00:00:00 2001
From: =?UTF-8?q?Sebastian=20Dr=C3=B6ge?= <sebastian@centricular.com>
Date: Wed, 17 Jun 2026 16:18:50 +0300
Subject: [PATCH] qtmoovrecover: Validate box sizes
Also validate box versions where it matters.
Fixes https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5118
Fixes https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5120
Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12041>
---
gst/isomp4/atomsrecovery.c | 88 ++++++++++++++++++++++++++++++++++++--
1 file changed, 84 insertions(+), 4 deletions(-)
diff --git a/gst/isomp4/atomsrecovery.c b/gst/isomp4/atomsrecovery.c
index edc4434..1761854 100644
--- a/gst/isomp4/atomsrecovery.c
+++ b/gst/isomp4/atomsrecovery.c
@@ -283,6 +283,8 @@ moov_recov_file_parse_prefix (MoovRecovFile * moovrf)
if (!read_atom_header (moovrf->file, &fourcc, &size)) {
return FALSE;
}
+ if (size < 8)
+ return FALSE;
if (fourcc != FOURCC_ftyp) {
/* we might have a prefix here */
@@ -294,6 +296,8 @@ moov_recov_file_parse_prefix (MoovRecovFile * moovrf)
/* now read the ftyp */
if (!read_atom_header (moovrf->file, &fourcc, &size))
return FALSE;
+ if (size < 8)
+ return FALSE;
}
/* this has to be the ftyp */
@@ -315,12 +319,25 @@ moov_recov_file_parse_mvhd (MoovRecovFile * moovrf)
/* check for sanity */
if (fourcc != FOURCC_mvhd)
return FALSE;
+ if (size < 8)
+ return FALSE;
moovrf->mvhd_size = size;
moovrf->mvhd_pos = ftell (moovrf->file) - 8;
+ guint8 version;
+ if (fread (&version, 1, 1, moovrf->file) != 1)
+ return FALSE;
+ if (version != 0) {
+ GST_WARNING ("Version %d mvhd not supported", version);
+ return FALSE;
+ }
+
+ if (size != 108)
+ return FALSE;
+
/* skip the remaining of the mvhd in the file */
- return fseek (moovrf->file, size - 8, SEEK_CUR) == 0;
+ return fseek (moovrf->file, size - 8 - 1, SEEK_CUR) == 0;
}
static gboolean
@@ -357,6 +374,8 @@ mdat_recov_file_find_mdat (FILE * file, GError ** err)
case FOURCC_ftyp:
case FOURCC_free:
case FOURCC_udta:
+ if (size < 8)
+ return FALSE;
if (fseek (file, size - 8, SEEK_CUR) != 0) {
goto file_seek_error;
}
@@ -486,6 +505,8 @@ skip_atom (MoovRecovFile * moovrf, guint32 expected_fourcc)
return FALSE;
if (fourcc != expected_fourcc)
return FALSE;
+ if (size < 8)
+ return FALSE;
return (fseek (moovrf->file, size - 8, SEEK_CUR) == 0);
}
@@ -502,11 +523,24 @@ moov_recov_parse_tkhd (MoovRecovFile * moovrf, TrakRecovData * trakrd)
return FALSE;
if (fourcc != FOURCC_tkhd)
return FALSE;
+ if (size < 8)
+ return FALSE;
trakrd->tkhd_file_offset = ftell (moovrf->file) - 8;
- /* move 8 bytes forward to the trak_id pos */
- if (fseek (moovrf->file, 12, SEEK_CUR) != 0)
+ guint8 version;
+ if (fread (&version, 1, 1, moovrf->file) != 1)
+ return FALSE;
+ if (version != 0) {
+ GST_WARNING ("Version %d tkhd not supported", version);
+ return FALSE;
+ }
+
+ if (size != 92)
+ return FALSE;
+
+ /* move 12-1 bytes forward to the trak_id pos */
+ if (fseek (moovrf->file, 12 - 1, SEEK_CUR) != 0)
return FALSE;
if (fread (data, 1, 4, moovrf->file) != 4)
return FALSE;
@@ -530,6 +564,8 @@ moov_recov_parse_stbl (MoovRecovFile * moovrf, TrakRecovData * trakrd)
return FALSE;
if (fourcc != FOURCC_stbl)
return FALSE;
+ if (size < 8)
+ return FALSE;
trakrd->stbl_file_offset = ftell (moovrf->file) - 8;
trakrd->stbl_size = size;
@@ -539,12 +575,17 @@ moov_recov_parse_stbl (MoovRecovFile * moovrf, TrakRecovData * trakrd)
return FALSE;
if (fourcc != FOURCC_stsd)
return FALSE;
+ if (auxsize < 8)
+ return FALSE;
if (fseek (moovrf->file, auxsize - 8, SEEK_CUR) != 0)
return FALSE;
trakrd->stsd_size = auxsize;
trakrd->post_stsd_offset = ftell (moovrf->file);
+ if (trakrd->stbl_size < trakrd->post_stsd_offset - trakrd->stbl_file_offset)
+ return FALSE;
+
/* as this is the last atom we parse, we don't skip forward */
return TRUE;
@@ -556,11 +597,14 @@ moov_recov_parse_minf (MoovRecovFile * moovrf, TrakRecovData * trakrd)
guint32 size;
guint32 fourcc;
guint32 auxsize;
+ guint64 offset;
if (!read_atom_header (moovrf->file, &fourcc, &size))
return FALSE;
if (fourcc != FOURCC_minf)
return FALSE;
+ if (size < 8)
+ return FALSE;
trakrd->minf_file_offset = ftell (moovrf->file) - 8;
trakrd->minf_size = size;
@@ -571,17 +615,23 @@ moov_recov_parse_minf (MoovRecovFile * moovrf, TrakRecovData * trakrd)
if (fourcc != FOURCC_vmhd && fourcc != FOURCC_smhd && fourcc != FOURCC_hmhd &&
fourcc != FOURCC_gmhd)
return FALSE;
+ if (auxsize < 8)
+ return FALSE;
if (fseek (moovrf->file, auxsize - 8, SEEK_CUR))
return FALSE;
/* skip a possible hdlr and the following dinf */
if (!read_atom_header (moovrf->file, &fourcc, &auxsize))
return FALSE;
+ if (auxsize < 8)
+ return FALSE;
if (fourcc == FOURCC_hdlr) {
if (fseek (moovrf->file, auxsize - 8, SEEK_CUR))
return FALSE;
if (!read_atom_header (moovrf->file, &fourcc, &auxsize))
return FALSE;
+ if (auxsize < 8)
+ return FALSE;
}
if (fourcc != FOURCC_dinf)
return FALSE;
@@ -592,6 +642,10 @@ moov_recov_parse_minf (MoovRecovFile * moovrf, TrakRecovData * trakrd)
if (!moov_recov_parse_stbl (moovrf, trakrd))
return FALSE;
+ offset = ftell (moovrf->file);
+ if (trakrd->minf_size < offset - trakrd->minf_file_offset)
+ return FALSE;
+
return TRUE;
}
@@ -607,11 +661,24 @@ moov_recov_parse_mdhd (MoovRecovFile * moovrf, TrakRecovData * trakrd)
return FALSE;
if (fourcc != FOURCC_mdhd)
return FALSE;
+ if (size < 8)
+ return FALSE;
trakrd->mdhd_file_offset = ftell (moovrf->file) - 8;
+ guint8 version;
+ if (fread (&version, 1, 1, moovrf->file) != 1)
+ return FALSE;
+ if (version != 0) {
+ GST_WARNING ("Version %d mdhd not supported", version);
+ return FALSE;
+ }
+
+ if (size != 32)
+ return FALSE;
+
/* get the timescale */
- if (fseek (moovrf->file, 12, SEEK_CUR) != 0)
+ if (fseek (moovrf->file, 12 - 1, SEEK_CUR) != 0)
return FALSE;
if (fread (data, 1, 4, moovrf->file) != 4)
return FALSE;
@@ -626,12 +693,15 @@ moov_recov_parse_mdia (MoovRecovFile * moovrf, TrakRecovData * trakrd)
{
guint32 size;
guint32 fourcc;
+ guint64 offset;
/* make sure we are on a tkhd atom */
if (!read_atom_header (moovrf->file, &fourcc, &size))
return FALSE;
if (fourcc != FOURCC_mdia)
return FALSE;
+ if (size < 8)
+ return FALSE;
trakrd->mdia_file_offset = ftell (moovrf->file) - 8;
trakrd->mdia_size = size;
@@ -643,6 +713,11 @@ moov_recov_parse_mdia (MoovRecovFile * moovrf, TrakRecovData * trakrd)
return FALSE;
if (!moov_recov_parse_minf (moovrf, trakrd))
return FALSE;
+
+ offset = ftell (moovrf->file);
+ if (trakrd->mdia_size < offset - trakrd->mdia_file_offset)
+ return FALSE;
+
return TRUE;
}
@@ -665,6 +740,8 @@ moov_recov_parse_trak (MoovRecovFile * moovrf, TrakRecovData * trakrd)
if (fourcc != FOURCC_trak) {
return FALSE;
}
+ if (size < 8)
+ return FALSE;
trakrd->trak_size = size;
/* now we should have a trak header 'tkhd' */
@@ -683,6 +760,9 @@ moov_recov_parse_trak (MoovRecovFile * moovrf, TrakRecovData * trakrd)
return FALSE;
trakrd->extra_atoms_offset = ftell (moovrf->file);
+ if (trakrd->trak_size < trakrd->extra_atoms_offset - offset)
+ return FALSE;
+
trakrd->extra_atoms_size = size - (trakrd->extra_atoms_offset - offset);
trakrd->file_offset = offset;

View File

@ -0,0 +1,66 @@
From 6f1894e23e665cb538051f301a6318850e601c5a Mon Sep 17 00:00:00 2001
From: =?UTF-8?q?Sebastian=20Dr=C3=B6ge?= <sebastian@centricular.com>
Date: Fri, 19 Jun 2026 13:20:04 +0300
Subject: [PATCH] gdkpixbufdec: Handle format and resolution changes correctly
Fixes https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5121
Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12043>
---
ext/gdk_pixbuf/gstgdkpixbufdec.c | 31 ++++++++++++++++---------------
1 file changed, 16 insertions(+), 15 deletions(-)
diff --git a/ext/gdk_pixbuf/gstgdkpixbufdec.c b/ext/gdk_pixbuf/gstgdkpixbufdec.c
index c0ecb3a..4472e79 100644
--- a/ext/gdk_pixbuf/gstgdkpixbufdec.c
+++ b/ext/gdk_pixbuf/gstgdkpixbufdec.c
@@ -289,6 +289,7 @@ gst_gdk_pixbuf_dec_flush (GstGdkPixbufDec * filter)
gint width, height;
gint n_channels;
GstVideoFrame frame;
+ GstVideoFormat fmt;
pixbuf = gdk_pixbuf_loader_get_pixbuf (filter->pixbuf_loader);
if (pixbuf == NULL)
@@ -297,26 +298,26 @@ gst_gdk_pixbuf_dec_flush (GstGdkPixbufDec * filter)
width = gdk_pixbuf_get_width (pixbuf);
height = gdk_pixbuf_get_height (pixbuf);
- if (GST_VIDEO_INFO_FORMAT (&filter->info) == GST_VIDEO_FORMAT_UNKNOWN) {
+ n_channels = gdk_pixbuf_get_n_channels (pixbuf);
+ switch (n_channels) {
+ case 3:
+ fmt = GST_VIDEO_FORMAT_RGB;
+ break;
+ case 4:
+ fmt = GST_VIDEO_FORMAT_RGBA;
+ break;
+ default:
+ goto channels_not_supported;
+ }
+
+ if (GST_VIDEO_INFO_FORMAT (&filter->info) != fmt ||
+ GST_VIDEO_INFO_WIDTH (&filter->info) != width ||
+ GST_VIDEO_INFO_HEIGHT (&filter->info) != height) {
GstVideoInfo info;
- GstVideoFormat fmt;
GList *l;
GST_DEBUG ("Set size to %dx%d", width, height);
- n_channels = gdk_pixbuf_get_n_channels (pixbuf);
- switch (n_channels) {
- case 3:
- fmt = GST_VIDEO_FORMAT_RGB;
- break;
- case 4:
- fmt = GST_VIDEO_FORMAT_RGBA;
- break;
- default:
- goto channels_not_supported;
- }
-
-
gst_video_info_init (&info);
if (!gst_video_info_set_format (&info, fmt, width, height))
goto format_not_supported;

View File

@ -0,0 +1,111 @@
From bbd02aa9846afe23511f6da40d55ebf19297c1a1 Mon Sep 17 00:00:00 2001
From: =?UTF-8?q?Sebastian=20Dr=C3=B6ge?= <sebastian@centricular.com>
Date: Fri, 19 Jun 2026 12:50:32 +0300
Subject: [PATCH 1/3] rtpsbcdepay: Check for available data in the adapter
before getting data
Consider empty packets with the last flag as bad packets.
Also reset buffers to NULL after giving away ownership of them to avoid
returning an already freed buffer.
Fixes https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5119
Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12042>
---
gst/rtp/gstrtpsbcdepay.c | 29 ++++++++++++++++++-----------
1 file changed, 18 insertions(+), 11 deletions(-)
diff --git a/gst/rtp/gstrtpsbcdepay.c b/gst/rtp/gstrtpsbcdepay.c
index 9549bb0..8d416b0 100644
--- a/gst/rtp/gstrtpsbcdepay.c
+++ b/gst/rtp/gstrtpsbcdepay.c
@@ -324,19 +324,26 @@ gst_rtp_sbc_depay_process (GstRTPBaseDepayload * base, GstRTPBuffer * rtp)
}
gst_adapter_push (depay->adapter, data);
+ data = NULL;
if (last) {
- gint framelen, samples;
- guint8 header[4];
-
- data = gst_adapter_take_buffer (depay->adapter,
- gst_adapter_available (depay->adapter));
- gst_rtp_drop_non_audio_meta (depay, data);
-
- if (gst_buffer_extract (data, 0, &header, 4) != 4 ||
- gst_rtp_sbc_depay_get_params (depay, header,
- payload_len, &framelen, &samples) < 0) {
- gst_buffer_unref (data);
+ if (gst_adapter_available (depay->adapter)) {
+ gint framelen, samples;
+ guint8 header[4];
+
+ data = gst_adapter_take_buffer (depay->adapter,
+ gst_adapter_available (depay->adapter));
+ gst_rtp_drop_non_audio_meta (depay, data);
+
+ if (gst_buffer_extract (data, 0, &header, 4) != 4 ||
+ gst_rtp_sbc_depay_get_params (depay, header,
+ payload_len, &framelen, &samples) < 0) {
+ gst_buffer_unref (data);
+ data = NULL;
+ goto bad_packet;
+ }
+ } else {
+ data = NULL;
goto bad_packet;
}
} else {
From c3fe759262470cb02cd098a488ac64cd27ace43f Mon Sep 17 00:00:00 2001
From: =?UTF-8?q?Sebastian=20Dr=C3=B6ge?= <sebastian@centricular.com>
Date: Fri, 19 Jun 2026 12:55:34 +0300
Subject: [PATCH 2/3] rtpsbcdepay: Check that enough data is available for the
payload header
Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12042>
---
gst/rtp/gstrtpsbcdepay.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/gst/rtp/gstrtpsbcdepay.c b/gst/rtp/gstrtpsbcdepay.c
index 8d416b0..d9fd005 100644
--- a/gst/rtp/gstrtpsbcdepay.c
+++ b/gst/rtp/gstrtpsbcdepay.c
@@ -297,6 +297,8 @@ gst_rtp_sbc_depay_process (GstRTPBaseDepayload * base, GstRTPBuffer * rtp)
payload = gst_rtp_buffer_get_payload (rtp);
payload_len = gst_rtp_buffer_get_payload_len (rtp);
+ if (payload_len < 1)
+ goto bad_packet;
fragment = payload[0] & 0x80;
start = payload[0] & 0x40;
From 511581656f27df4251f05568718346a8d6bf775c Mon Sep 17 00:00:00 2001
From: =?UTF-8?q?Sebastian=20Dr=C3=B6ge?= <sebastian@centricular.com>
Date: Fri, 19 Jun 2026 13:00:27 +0300
Subject: [PATCH 3/3] rtpsbcdepay: Remove wrong variable shadowing
`samples` is expected to be set in the outer scope at a later time.
Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12042>
---
gst/rtp/gstrtpsbcdepay.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/gst/rtp/gstrtpsbcdepay.c b/gst/rtp/gstrtpsbcdepay.c
index d9fd005..280c41b 100644
--- a/gst/rtp/gstrtpsbcdepay.c
+++ b/gst/rtp/gstrtpsbcdepay.c
@@ -330,7 +330,7 @@ gst_rtp_sbc_depay_process (GstRTPBaseDepayload * base, GstRTPBuffer * rtp)
if (last) {
if (gst_adapter_available (depay->adapter)) {
- gint framelen, samples;
+ gint framelen;
guint8 header[4];
data = gst_adapter_take_buffer (depay->adapter,

View File

@ -15,7 +15,7 @@
Name: gstreamer1-plugins-good
Version: 1.16.1
Release: 7%{?gitcommit:.git%{shortcommit}}%{?dist}.3
Release: 7%{?gitcommit:.git%{shortcommit}}%{?dist}.7
Summary: GStreamer plugins with good code and licensing
License: LGPLv2+
@ -51,6 +51,17 @@ Patch12: gstreamer1-plugins-good-1.16.1-CVE-2026-18649.patch
# https://issues.redhat.com/browse/RHEL-239048
# https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/0bcc6564c7deedc7d6d7373a2ab6479c9bf3889f
Patch13: gstreamer1-plugins-good-1.16.1-CVE-2026-73434.patch
# https://issues.redhat.com/browse/RHEL-246549
# https://issues.redhat.com/browse/RHEL-246382
# https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/93fa4cd30ba43b38b02a9de76a7a80dc198c87a0
# https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12041
Patch14: gstreamer1-plugins-good-1.16.1-CVE-2026-18296.patch
# https://issues.redhat.com/browse/RHEL-246618
# https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12042
Patch15: gstreamer1-plugins-good-1.16.1-CVE-2026-18299.patch
# https://issues.redhat.com/browse/RHEL-246561
# https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/cf4f7cbc081cde7769862b424c105f10c083171b
Patch16: gstreamer1-plugins-good-1.16.1-CVE-2026-18298.patch
BuildRequires: gcc
BuildRequires: gcc-c++
@ -198,6 +209,9 @@ to be installed.
%patch11 -p1
%patch12 -p1
%patch13 -p1
%patch14 -p1
%patch15 -p1
%patch16 -p1
%build
%configure --disable-silent-rules --disable-fatal-warnings \
@ -382,6 +396,23 @@ find $RPM_BUILD_ROOT -name '*.la' -exec rm -f {} ';'
%changelog
* Sat Aug 22 2026 RHEL Packaging Agent <redhat-ymir-agent@redhat.com> - 1.16.1-7.7
- Fix CVE-2026-18296: heap buffer overflow in qtmoovrecover
Resolves: RHEL-246382
* Sat Aug 22 2026 RHEL Packaging Agent <redhat-ymir-agent@redhat.com> - 1.16.1-7.6
- Fix CVE-2026-18298: heap buffer overflow in GdkPixbuf image decoder
Resolves: RHEL-246561
* Sat Aug 22 2026 RHEL Packaging Agent <redhat-ymir-agent@redhat.com> - 1.16.1-7.5
- Fix CVE-2026-18299: Use-After-Free in rtpsbcdepay
Resolves: RHEL-246618
* Sat Aug 22 2026 RHEL Packaging Agent <redhat-ymir-agent@redhat.com> - 1.16.1-7.4
- Fix CVE-2026-18296: validate box sizes and versions in
qtmoovrecover (atomsrecovery)
Resolves: RHEL-246549
* Thu Aug 13 2026 RHEL Packaging Agent <redhat-ymir-agent@redhat.com> - 1.16.1-7.3
- Fix CVE-2026-73434: out-of-bounds read in AVI demuxer vprp handling
Resolves: RHEL-239048