diff --git a/gstreamer1-plugins-good-1.16.1-CVE-2026-73433.patch b/gstreamer1-plugins-good-1.16.1-CVE-2026-73433.patch index 986b84c..b56c21e 100644 --- a/gstreamer1-plugins-good-1.16.1-CVE-2026-73433.patch +++ b/gstreamer1-plugins-good-1.16.1-CVE-2026-73433.patch @@ -363,3 +363,52 @@ index 20fd207..4d3f608 100644 empty_index: { GST_DEBUG_OBJECT (avi, "the index is empty"); +-- +2.45.0 + +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Tomas Pelka +Date: Mon, 24 Aug 2026 12:00:00 +0200 +Subject: [PATCH] avidemux: Add GLib < 2.68 compatibility shim for g_memdup2 + +Downstream-only adaptation, not an upstream commit. + +The preceding commit ("avidemux: Don't modify read-only mapped buffer +data", part of upstream MR !12231 / the CVE-2026-73433 fix) introduces +two calls to g_memdup2() in gst_avi_demux_parse_strd() and +gst_avi_demux_parse_ncdt(). g_memdup2() was only added in GLib 2.68; +RHEL 8 ships GLib 2.56.4. Since GStreamer elements are dlopen-loaded +plugins, the missing symbol does not fail the build -- it fails at +plugin load time with "undefined symbol: g_memdup2", silently +disabling the entire avi plugin (avidemux/avimux). See RHEL-246869. + +Upstream does not need this because gstreamer's own +gst/glib-compat-private.h already provides this fallback macro for +GLib < 2.67.4 builds (see commit b16e96dd87 in the gstreamer +monorepo), and meson wires it into config.h automatically. That +mechanism is not part of this 1.16.1 autotools-based tree, so provide +the same macro directly in gstavidemux.c ahead of its first use. +--- + gst/avi/gstavidemux.c | 9 +++++++++ + 1 file changed, 9 insertions(+) + +diff --git a/gst/avi/gstavidemux.c b/gst/avi/gstavidemux.c +index 834af76..a897bd8 100644 +--- a/gst/avi/gstavidemux.c ++++ b/gst/avi/gstavidemux.c +@@ -53,6 +53,15 @@ + #include + #include + ++/* g_memdup2() was only added in GLib 2.68. Provide the same fallback ++ * that GStreamer itself ships in gst/glib-compat-private.h for builds ++ * against older GLib (e.g. RHEL 8's GLib 2.56), so that using ++ * g_memdup2() below does not turn into an unresolved symbol at ++ * runtime. */ ++#if !GLIB_CHECK_VERSION(2, 67, 4) ++#define g_memdup2(ptr,sz) ((G_LIKELY(((guint64)(sz)) < G_MAXUINT)) ? g_memdup(ptr,sz) : (g_abort(),NULL)) ++#endif ++ + #define DIV_ROUND_UP(s,v) (((s) + ((v)-1)) / (v)) + + #define GST_AVI_KEYFRAME (1 << 0) diff --git a/gstreamer1-plugins-good.spec b/gstreamer1-plugins-good.spec index b6e3fa0..ea2f8bd 100644 --- a/gstreamer1-plugins-good.spec +++ b/gstreamer1-plugins-good.spec @@ -15,7 +15,7 @@ Name: gstreamer1-plugins-good Version: 1.16.1 -Release: 7%{?gitcommit:.git%{shortcommit}}%{?dist}.7 +Release: 7%{?gitcommit:.git%{shortcommit}}%{?dist}.8 Summary: GStreamer plugins with good code and licensing License: LGPLv2+ @@ -396,6 +396,12 @@ find $RPM_BUILD_ROOT -name '*.la' -exec rm -f {} ';' %changelog +* Mon Aug 24 2026 Tomas Pelka - 1.16.1-7.8 +- avidemux: add GLib < 2.68 compatibility shim for g_memdup2, used by + the CVE-2026-73433 fix; without it the avi plugin fails to load on + RHEL 8 (GLib 2.56) with "undefined symbol: g_memdup2" + Resolves: RHEL-246869 + * Sat Aug 22 2026 RHEL Packaging Agent - 1.16.1-7.7 - Fix CVE-2026-18296: heap buffer overflow in qtmoovrecover Resolves: RHEL-246382