import Oracle_OSS gstreamer1-plugins-good-1.26.7-2.el10_2.7

This commit is contained in:
AlmaLinux RelEng Bot 2026-08-25 05:50:51 -04:00
parent c0a04e4244
commit cce5ea68bb
3 changed files with 389 additions and 1 deletions

View File

@ -0,0 +1,262 @@
From 93fa4cd30ba43b38b02a9de76a7a80dc198c87a0 Mon Sep 17 00:00:00 2001
From: =?UTF-8?q?Sebastian=20Dr=C3=B6ge?= <sebastian@centricular.com>
Date: Wed, 17 Jun 2026 16:18:50 +0300
Subject: [PATCH] qtmoovrecover: Validate box sizes
Also validate box versions where it matters.
Fixes https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5118
Fixes https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5120
Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12041>
---
.../gst/isomp4/atomsrecovery.c | 88 ++++++++++++++++++-
1 file changed, 84 insertions(+), 4 deletions(-)
diff --git a/subprojects/gst-plugins-good/gst/isomp4/atomsrecovery.c b/subprojects/gst-plugins-good/gst/isomp4/atomsrecovery.c
index edc443487b3..176185476fa 100644
--- a/subprojects/gst-plugins-good/gst/isomp4/atomsrecovery.c
+++ b/subprojects/gst-plugins-good/gst/isomp4/atomsrecovery.c
@@ -283,6 +283,8 @@ moov_recov_file_parse_prefix (MoovRecovFile * moovrf)
if (!read_atom_header (moovrf->file, &fourcc, &size)) {
return FALSE;
}
+ if (size < 8)
+ return FALSE;
if (fourcc != FOURCC_ftyp) {
/* we might have a prefix here */
@@ -294,6 +296,8 @@ moov_recov_file_parse_prefix (MoovRecovFile * moovrf)
/* now read the ftyp */
if (!read_atom_header (moovrf->file, &fourcc, &size))
return FALSE;
+ if (size < 8)
+ return FALSE;
}
/* this has to be the ftyp */
@@ -315,12 +319,25 @@ moov_recov_file_parse_mvhd (MoovRecovFile * moovrf)
/* check for sanity */
if (fourcc != FOURCC_mvhd)
return FALSE;
+ if (size < 8)
+ return FALSE;
moovrf->mvhd_size = size;
moovrf->mvhd_pos = ftell (moovrf->file) - 8;
+ guint8 version;
+ if (fread (&version, 1, 1, moovrf->file) != 1)
+ return FALSE;
+ if (version != 0) {
+ GST_WARNING ("Version %d mvhd not supported", version);
+ return FALSE;
+ }
+
+ if (size != 108)
+ return FALSE;
+
/* skip the remaining of the mvhd in the file */
- return fseek (moovrf->file, size - 8, SEEK_CUR) == 0;
+ return fseek (moovrf->file, size - 8 - 1, SEEK_CUR) == 0;
}
static gboolean
@@ -357,6 +374,8 @@ mdat_recov_file_find_mdat (FILE * file, GError ** err)
case FOURCC_ftyp:
case FOURCC_free:
case FOURCC_udta:
+ if (size < 8)
+ return FALSE;
if (fseek (file, size - 8, SEEK_CUR) != 0) {
goto file_seek_error;
}
@@ -486,6 +505,8 @@ skip_atom (MoovRecovFile * moovrf, guint32 expected_fourcc)
return FALSE;
if (fourcc != expected_fourcc)
return FALSE;
+ if (size < 8)
+ return FALSE;
return (fseek (moovrf->file, size - 8, SEEK_CUR) == 0);
}
@@ -502,11 +523,24 @@ moov_recov_parse_tkhd (MoovRecovFile * moovrf, TrakRecovData * trakrd)
return FALSE;
if (fourcc != FOURCC_tkhd)
return FALSE;
+ if (size < 8)
+ return FALSE;
trakrd->tkhd_file_offset = ftell (moovrf->file) - 8;
- /* move 8 bytes forward to the trak_id pos */
- if (fseek (moovrf->file, 12, SEEK_CUR) != 0)
+ guint8 version;
+ if (fread (&version, 1, 1, moovrf->file) != 1)
+ return FALSE;
+ if (version != 0) {
+ GST_WARNING ("Version %d tkhd not supported", version);
+ return FALSE;
+ }
+
+ if (size != 92)
+ return FALSE;
+
+ /* move 12-1 bytes forward to the trak_id pos */
+ if (fseek (moovrf->file, 12 - 1, SEEK_CUR) != 0)
return FALSE;
if (fread (data, 1, 4, moovrf->file) != 4)
return FALSE;
@@ -530,6 +564,8 @@ moov_recov_parse_stbl (MoovRecovFile * moovrf, TrakRecovData * trakrd)
return FALSE;
if (fourcc != FOURCC_stbl)
return FALSE;
+ if (size < 8)
+ return FALSE;
trakrd->stbl_file_offset = ftell (moovrf->file) - 8;
trakrd->stbl_size = size;
@@ -539,12 +575,17 @@ moov_recov_parse_stbl (MoovRecovFile * moovrf, TrakRecovData * trakrd)
return FALSE;
if (fourcc != FOURCC_stsd)
return FALSE;
+ if (auxsize < 8)
+ return FALSE;
if (fseek (moovrf->file, auxsize - 8, SEEK_CUR) != 0)
return FALSE;
trakrd->stsd_size = auxsize;
trakrd->post_stsd_offset = ftell (moovrf->file);
+ if (trakrd->stbl_size < trakrd->post_stsd_offset - trakrd->stbl_file_offset)
+ return FALSE;
+
/* as this is the last atom we parse, we don't skip forward */
return TRUE;
@@ -556,11 +597,14 @@ moov_recov_parse_minf (MoovRecovFile * moovrf, TrakRecovData * trakrd)
guint32 size;
guint32 fourcc;
guint32 auxsize;
+ guint64 offset;
if (!read_atom_header (moovrf->file, &fourcc, &size))
return FALSE;
if (fourcc != FOURCC_minf)
return FALSE;
+ if (size < 8)
+ return FALSE;
trakrd->minf_file_offset = ftell (moovrf->file) - 8;
trakrd->minf_size = size;
@@ -571,17 +615,23 @@ moov_recov_parse_minf (MoovRecovFile * moovrf, TrakRecovData * trakrd)
if (fourcc != FOURCC_vmhd && fourcc != FOURCC_smhd && fourcc != FOURCC_hmhd &&
fourcc != FOURCC_gmhd)
return FALSE;
+ if (auxsize < 8)
+ return FALSE;
if (fseek (moovrf->file, auxsize - 8, SEEK_CUR))
return FALSE;
/* skip a possible hdlr and the following dinf */
if (!read_atom_header (moovrf->file, &fourcc, &auxsize))
return FALSE;
+ if (auxsize < 8)
+ return FALSE;
if (fourcc == FOURCC_hdlr) {
if (fseek (moovrf->file, auxsize - 8, SEEK_CUR))
return FALSE;
if (!read_atom_header (moovrf->file, &fourcc, &auxsize))
return FALSE;
+ if (auxsize < 8)
+ return FALSE;
}
if (fourcc != FOURCC_dinf)
return FALSE;
@@ -592,6 +642,10 @@ moov_recov_parse_minf (MoovRecovFile * moovrf, TrakRecovData * trakrd)
if (!moov_recov_parse_stbl (moovrf, trakrd))
return FALSE;
+ offset = ftell (moovrf->file);
+ if (trakrd->minf_size < offset - trakrd->minf_file_offset)
+ return FALSE;
+
return TRUE;
}
@@ -607,11 +661,24 @@ moov_recov_parse_mdhd (MoovRecovFile * moovrf, TrakRecovData * trakrd)
return FALSE;
if (fourcc != FOURCC_mdhd)
return FALSE;
+ if (size < 8)
+ return FALSE;
trakrd->mdhd_file_offset = ftell (moovrf->file) - 8;
+ guint8 version;
+ if (fread (&version, 1, 1, moovrf->file) != 1)
+ return FALSE;
+ if (version != 0) {
+ GST_WARNING ("Version %d mdhd not supported", version);
+ return FALSE;
+ }
+
+ if (size != 32)
+ return FALSE;
+
/* get the timescale */
- if (fseek (moovrf->file, 12, SEEK_CUR) != 0)
+ if (fseek (moovrf->file, 12 - 1, SEEK_CUR) != 0)
return FALSE;
if (fread (data, 1, 4, moovrf->file) != 4)
return FALSE;
@@ -626,12 +693,15 @@ moov_recov_parse_mdia (MoovRecovFile * moovrf, TrakRecovData * trakrd)
{
guint32 size;
guint32 fourcc;
+ guint64 offset;
/* make sure we are on a tkhd atom */
if (!read_atom_header (moovrf->file, &fourcc, &size))
return FALSE;
if (fourcc != FOURCC_mdia)
return FALSE;
+ if (size < 8)
+ return FALSE;
trakrd->mdia_file_offset = ftell (moovrf->file) - 8;
trakrd->mdia_size = size;
@@ -643,6 +713,11 @@ moov_recov_parse_mdia (MoovRecovFile * moovrf, TrakRecovData * trakrd)
return FALSE;
if (!moov_recov_parse_minf (moovrf, trakrd))
return FALSE;
+
+ offset = ftell (moovrf->file);
+ if (trakrd->mdia_size < offset - trakrd->mdia_file_offset)
+ return FALSE;
+
return TRUE;
}
@@ -665,6 +740,8 @@ moov_recov_parse_trak (MoovRecovFile * moovrf, TrakRecovData * trakrd)
if (fourcc != FOURCC_trak) {
return FALSE;
}
+ if (size < 8)
+ return FALSE;
trakrd->trak_size = size;
/* now we should have a trak header 'tkhd' */
@@ -683,6 +760,9 @@ moov_recov_parse_trak (MoovRecovFile * moovrf, TrakRecovData * trakrd)
return FALSE;
trakrd->extra_atoms_offset = ftell (moovrf->file);
+ if (trakrd->trak_size < trakrd->extra_atoms_offset - offset)
+ return FALSE;
+
trakrd->extra_atoms_size = size - (trakrd->extra_atoms_offset - offset);
trakrd->file_offset = offset;
--
GitLab

View File

@ -0,0 +1,113 @@
From ea62ef84c0300c97f4831f90ab1adb183eaffb9d Mon Sep 17 00:00:00 2001
From: =?UTF-8?q?Sebastian=20Dr=C3=B6ge?= <sebastian@centricular.com>
Date: Fri, 19 Jun 2026 13:15:02 +0300
Subject: [PATCH 1/2] gdkpixbufdec: Drop rank to NONE
gdk-pixbuf is not mean to be used on untrusted inputs so let's not ask for
problems here.
For the common image formats we have specialized elements with higher ranks and
for a proper replacement follow this issue:
https://gitlab.freedesktop.org/gstreamer/gst-plugins-rs/-/issues/764
Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12043>
---
subprojects/gst-plugins-good/docs/gst_plugins_cache.json | 2 +-
subprojects/gst-plugins-good/ext/gdk_pixbuf/gstgdkpixbufdec.c | 3 +--
2 files changed, 2 insertions(+), 3 deletions(-)
diff --git a/subprojects/gst-plugins-good/docs/gst_plugins_cache.json b/subprojects/gst-plugins-good/docs/gst_plugins_cache.json
index f22df3a..b7ef532 100644
--- a/subprojects/gst-plugins-good/docs/gst_plugins_cache.json
+++ b/subprojects/gst-plugins-good/docs/gst_plugins_cache.json
@@ -7507,7 +7507,7 @@
"presence": "always"
}
},
- "rank": "secondary"
+ "rank": "none"
},
"gdkpixbufoverlay": {
"author": "Tim-Philipp Müller <tim centricular net>",
diff --git a/subprojects/gst-plugins-good/ext/gdk_pixbuf/gstgdkpixbufdec.c b/subprojects/gst-plugins-good/ext/gdk_pixbuf/gstgdkpixbufdec.c
index de5f054..3279e48 100644
--- a/subprojects/gst-plugins-good/ext/gdk_pixbuf/gstgdkpixbufdec.c
+++ b/subprojects/gst-plugins-good/ext/gdk_pixbuf/gstgdkpixbufdec.c
@@ -76,8 +76,7 @@ static gboolean gst_gdk_pixbuf_dec_sink_event (GstPad * pad, GstObject * parent,
#define gst_gdk_pixbuf_dec_parent_class parent_class
G_DEFINE_TYPE (GstGdkPixbufDec, gst_gdk_pixbuf_dec, GST_TYPE_ELEMENT);
GST_ELEMENT_REGISTER_DEFINE_WITH_CODE (gdkpixbufdec, "gdkpixbufdec",
- GST_RANK_SECONDARY, GST_TYPE_GDK_PIXBUF_DEC,
- gdk_pixbuf_element_init (plugin));
+ GST_RANK_NONE, GST_TYPE_GDK_PIXBUF_DEC, gdk_pixbuf_element_init (plugin));
static gboolean
gst_gdk_pixbuf_dec_sink_setcaps (GstGdkPixbufDec * filter, GstCaps * caps)
From 2cf57a6248bd388d93f56efb342a8425bd0d1142 Mon Sep 17 00:00:00 2001
From: =?UTF-8?q?Sebastian=20Dr=C3=B6ge?= <sebastian@centricular.com>
Date: Fri, 19 Jun 2026 13:20:04 +0300
Subject: [PATCH 2/2] gdkpixbufdec: Handle format and resolution changes
correctly
Fixes https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5121
Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12043>
---
subprojects/gst-plugins-good/ext/gdk_pixbuf/gstgdkpixbufdec.c | 31 ++++++++++++++++---------------
1 file changed, 16 insertions(+), 15 deletions(-)
diff --git a/subprojects/gst-plugins-good/ext/gdk_pixbuf/gstgdkpixbufdec.c b/subprojects/gst-plugins-good/ext/gdk_pixbuf/gstgdkpixbufdec.c
index 3279e48..103b0bd 100644
--- a/subprojects/gst-plugins-good/ext/gdk_pixbuf/gstgdkpixbufdec.c
+++ b/subprojects/gst-plugins-good/ext/gdk_pixbuf/gstgdkpixbufdec.c
@@ -292,6 +292,7 @@ gst_gdk_pixbuf_dec_flush (GstGdkPixbufDec * filter)
gint width, height;
gint n_channels;
GstVideoFrame frame;
+ GstVideoFormat fmt;
pixbuf = gdk_pixbuf_loader_get_pixbuf (filter->pixbuf_loader);
if (pixbuf == NULL)
@@ -300,26 +301,26 @@ gst_gdk_pixbuf_dec_flush (GstGdkPixbufDec * filter)
width = gdk_pixbuf_get_width (pixbuf);
height = gdk_pixbuf_get_height (pixbuf);
- if (GST_VIDEO_INFO_FORMAT (&filter->info) == GST_VIDEO_FORMAT_UNKNOWN) {
+ n_channels = gdk_pixbuf_get_n_channels (pixbuf);
+ switch (n_channels) {
+ case 3:
+ fmt = GST_VIDEO_FORMAT_RGB;
+ break;
+ case 4:
+ fmt = GST_VIDEO_FORMAT_RGBA;
+ break;
+ default:
+ goto channels_not_supported;
+ }
+
+ if (GST_VIDEO_INFO_FORMAT (&filter->info) != fmt ||
+ GST_VIDEO_INFO_WIDTH (&filter->info) != width ||
+ GST_VIDEO_INFO_HEIGHT (&filter->info) != height) {
GstVideoInfo info;
- GstVideoFormat fmt;
GList *l;
GST_DEBUG ("Set size to %dx%d", width, height);
- n_channels = gdk_pixbuf_get_n_channels (pixbuf);
- switch (n_channels) {
- case 3:
- fmt = GST_VIDEO_FORMAT_RGB;
- break;
- case 4:
- fmt = GST_VIDEO_FORMAT_RGBA;
- break;
- default:
- goto channels_not_supported;
- }
-
-
gst_video_info_init (&info);
if (!gst_video_info_set_format (&info, fmt, width, height))
goto format_not_supported;

View File

@ -35,7 +35,7 @@
Name: gstreamer1-plugins-good
Version: 1.26.7
Release: 2%{?dist}.5
Release: 2%{?dist}.7
Summary: GStreamer plugins with good code and licensing
License: CC0-1.0 AND GPL-2.0-only AND LGPL-2.0-only AND LGPL-2.0-or-later AND LGPL-2.1-only AND LGPL-2.1-or-later AND xlock AND MIT AND BSD-3-Clause AND CC-BY-3.0
@ -69,6 +69,10 @@ Patch: gstreamer1-plugins-good-1.26.7-CVE-2026-18649.patch
Patch: gstreamer1-plugins-good-1.26.7-CVE-2026-73433.patch
# https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/0bcc6564c7deedc7d6d7373a2ab6479c9bf3889f
Patch: gstreamer1-plugins-good-1.26.7-CVE-2026-73434.patch
# https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12041
Patch: gstreamer1-plugins-good-1.26.7-CVE-2026-18296.patch
# https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12043
Patch: gstreamer1-plugins-good-1.26.7-CVE-2026-18298.patch
BuildRequires: meson >= 0.48.0
BuildRequires: gcc
@ -389,6 +393,15 @@ find $RPM_BUILD_ROOT -name '*.la' -exec rm -fv {} ';'
%changelog
* Sat Aug 22 2026 RHEL Packaging Agent <redhat-ymir-agent@redhat.com> - 1.26.7-2.7
- Fix CVE-2026-18298 in gdkpixbufdec element
Resolves: RHEL-246557
* Sat Aug 22 2026 RHEL Packaging Agent <redhat-ymir-agent@redhat.com> - 1.26.7-2.6
- Fix insufficient size validation in MRF file parsing in qtmoovrecover
(CVE-2026-18296)
Resolves: RHEL-246546
* Thu Aug 13 2026 RHEL Packaging Agent <redhat-ymir-agent@redhat.com> - 1.26.7-2.5
- Fix CVE-2026-73434: out-of-bounds read in AVI demuxer vprp handling
Resolves: RHEL-239045