From 8970e129a71249b021af36312f05fdb6837fd42e Mon Sep 17 00:00:00 2001 From: Tomas Pelka Date: Mon, 24 Aug 2026 14:57:03 +0200 Subject: [PATCH] avidemux: Add GLib < 2.68 compatibility shim for g_memdup2 RHEL-246869: the CVE-2026-73433 backport (Patch11) introduces two calls to g_memdup2() in gst/avi/gstavidemux.c (gst_avi_demux_parse_strd and gst_avi_demux_parse_ncdt). g_memdup2() was only added in GLib 2.68; RHEL 8 ships GLib 2.56.4. Since GStreamer elements are dlopen-loaded plugins, the missing symbol does not fail the build -- it fails at plugin load time with 'undefined symbol: g_memdup2', silently disabling the entire avi plugin (avidemux/avimux). There is no upstream commit to backport for this: upstream's own gst/glib-compat-private.h already provides this exact fallback macro for builds against GLib < 2.67.4 (see commit b16e96dd87 in the gstreamer monorepo), and meson wires it into config.h automatically. That mechanism doesn't exist in this 1.16.1 autotools-based tree, so add the same macro directly to gstavidemux.c ahead of its first use, as an additional hunk appended to the existing CVE-2026-73433 patch. This follows Option A from the Jira discussion (preferred by both the Ymir triage agent and Wim Taymans), matching the exact mechanism GStreamer itself uses rather than replacing g_memdup2 with a plain g_memdup call. Verified: applying the modified patch with "patch -p1" against a pristine gst-plugins-good-1.16.1 source tree succeeds cleanly (exit 0, no .rej files), with the compat macro defined before both g_memdup2 call sites. Resolves: RHEL-246869 --- ...1-plugins-good-1.16.1-CVE-2026-73433.patch | 49 +++++++++++++++++++ gstreamer1-plugins-good.spec | 8 ++- 2 files changed, 56 insertions(+), 1 deletion(-) diff --git a/gstreamer1-plugins-good-1.16.1-CVE-2026-73433.patch b/gstreamer1-plugins-good-1.16.1-CVE-2026-73433.patch index 986b84c..b56c21e 100644 --- a/gstreamer1-plugins-good-1.16.1-CVE-2026-73433.patch +++ b/gstreamer1-plugins-good-1.16.1-CVE-2026-73433.patch @@ -363,3 +363,52 @@ index 20fd207..4d3f608 100644 empty_index: { GST_DEBUG_OBJECT (avi, "the index is empty"); +-- +2.45.0 + +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Tomas Pelka +Date: Mon, 24 Aug 2026 12:00:00 +0200 +Subject: [PATCH] avidemux: Add GLib < 2.68 compatibility shim for g_memdup2 + +Downstream-only adaptation, not an upstream commit. + +The preceding commit ("avidemux: Don't modify read-only mapped buffer +data", part of upstream MR !12231 / the CVE-2026-73433 fix) introduces +two calls to g_memdup2() in gst_avi_demux_parse_strd() and +gst_avi_demux_parse_ncdt(). g_memdup2() was only added in GLib 2.68; +RHEL 8 ships GLib 2.56.4. Since GStreamer elements are dlopen-loaded +plugins, the missing symbol does not fail the build -- it fails at +plugin load time with "undefined symbol: g_memdup2", silently +disabling the entire avi plugin (avidemux/avimux). See RHEL-246869. + +Upstream does not need this because gstreamer's own +gst/glib-compat-private.h already provides this fallback macro for +GLib < 2.67.4 builds (see commit b16e96dd87 in the gstreamer +monorepo), and meson wires it into config.h automatically. That +mechanism is not part of this 1.16.1 autotools-based tree, so provide +the same macro directly in gstavidemux.c ahead of its first use. +--- + gst/avi/gstavidemux.c | 9 +++++++++ + 1 file changed, 9 insertions(+) + +diff --git a/gst/avi/gstavidemux.c b/gst/avi/gstavidemux.c +index 834af76..a897bd8 100644 +--- a/gst/avi/gstavidemux.c ++++ b/gst/avi/gstavidemux.c +@@ -53,6 +53,15 @@ + #include + #include + ++/* g_memdup2() was only added in GLib 2.68. Provide the same fallback ++ * that GStreamer itself ships in gst/glib-compat-private.h for builds ++ * against older GLib (e.g. RHEL 8's GLib 2.56), so that using ++ * g_memdup2() below does not turn into an unresolved symbol at ++ * runtime. */ ++#if !GLIB_CHECK_VERSION(2, 67, 4) ++#define g_memdup2(ptr,sz) ((G_LIKELY(((guint64)(sz)) < G_MAXUINT)) ? g_memdup(ptr,sz) : (g_abort(),NULL)) ++#endif ++ + #define DIV_ROUND_UP(s,v) (((s) + ((v)-1)) / (v)) + + #define GST_AVI_KEYFRAME (1 << 0) diff --git a/gstreamer1-plugins-good.spec b/gstreamer1-plugins-good.spec index b6e3fa0..ea2f8bd 100644 --- a/gstreamer1-plugins-good.spec +++ b/gstreamer1-plugins-good.spec @@ -15,7 +15,7 @@ Name: gstreamer1-plugins-good Version: 1.16.1 -Release: 7%{?gitcommit:.git%{shortcommit}}%{?dist}.7 +Release: 7%{?gitcommit:.git%{shortcommit}}%{?dist}.8 Summary: GStreamer plugins with good code and licensing License: LGPLv2+ @@ -396,6 +396,12 @@ find $RPM_BUILD_ROOT -name '*.la' -exec rm -f {} ';' %changelog +* Mon Aug 24 2026 Tomas Pelka - 1.16.1-7.8 +- avidemux: add GLib < 2.68 compatibility shim for g_memdup2, used by + the CVE-2026-73433 fix; without it the avi plugin fails to load on + RHEL 8 (GLib 2.56) with "undefined symbol: g_memdup2" + Resolves: RHEL-246869 + * Sat Aug 22 2026 RHEL Packaging Agent - 1.16.1-7.7 - Fix CVE-2026-18296: heap buffer overflow in qtmoovrecover Resolves: RHEL-246382