GStreamer plugins with good code and licensing
Go to file
RHEL Packaging Agent ef64522103 Fix CVE-2026-18299: Use-After-Free in rtpsbcdepay
Backport upstream MR 12042 to fix CVE-2026-18299 in the
rtpsbcdepay element. The patch includes three commits that
fix a use-after-free by resetting buffer pointers after
ownership transfer, add a payload length bounds check for
the payload header, and correct variable shadowing
introduced by the first fix.

CVE: CVE-2026-18299
Upstream patches:
 - https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12042.patch
Resolves: RHEL-246615

This commit was backported by Ymir, a Red Hat Enterprise Linux software maintenance AI agent.

Assisted-by: Ymir
2026-08-25 10:51:42 +00:00
.gitignore Update to 1.26.7 2025-11-04 17:24:03 +01:00
0001-jitterbuffer-Allow-rtp-caps-without-clock-rate.patch Don't force RTP jitterbuffer clock-rate 2015-03-06 16:57:25 +00:00
0001-rtpqdm2depay-error-out-if-anyone-tries-to-use-this-e.patch Add patch for CVE-2026-3083 and CVE-2026-3085 2026-03-31 11:39:29 +02:00
gating.yaml Add gating.yaml via API 2024-04-30 10:22:18 +00:00
gstreamer1-plugins-good-1.26.7-CVE-2026-5056.patch Fix CVE-2026-5056: bounds checks in qtdemux uncompressed video 2026-08-11 14:45:58 +00:00
gstreamer1-plugins-good-1.26.7-CVE-2026-18296.patch Fix CVE-2026-18296: heap buffer overflow in qtmoovrecover 2026-08-24 18:54:53 +00:00
gstreamer1-plugins-good-1.26.7-CVE-2026-18298.patch Fix CVE-2026-18298 in gdkpixbufdec element 2026-08-24 18:57:56 +00:00
gstreamer1-plugins-good-1.26.7-CVE-2026-18299.patch Fix CVE-2026-18299: Use-After-Free in rtpsbcdepay 2026-08-25 10:51:42 +00:00
gstreamer1-plugins-good-1.26.7-CVE-2026-18649.patch Fix CVE-2026-18649: limit RTP H.264/H.265 fragmentation unit size 2026-08-11 14:42:38 +00:00
gstreamer1-plugins-good-1.26.7-CVE-2026-53705.patch Fix integer overflow in wavpack decoder (CVE-2026-53705) 2026-07-29 08:38:47 +00:00
gstreamer1-plugins-good-1.26.7-CVE-2026-73433.patch Fix CVE-2026-73433: out-of-bounds reads in AVI FUJIFILM strd parsing 2026-08-18 15:50:58 +02:00
gstreamer1-plugins-good-1.26.7-CVE-2026-73434.patch Fix CVE-2026-73434: out-of-bounds read in AVI demuxer vprp handling 2026-08-18 15:50:58 +02:00
gstreamer1-plugins-good.spec Fix CVE-2026-18299: Use-After-Free in rtpsbcdepay 2026-08-25 10:51:42 +00:00
gstreamer-good.appdata.xml +appdata.xml 2018-05-22 13:28:23 -05:00
sources Update to 1.26.7 2025-11-04 17:24:03 +01:00