GStreamer streaming media framework "ugly" plugins
Go to file
Tomas Pelka 6908d98562 Fix OOB reads in realmedia demuxer (CVE-2026-53703, CVE-2026-53704)
Backport upstream MR !11832 (7 commits) from the GStreamer 1.24
branch to gstreamer1-plugins-ugly-free 1.22.12. The fixes address
integer overflow and out-of-bounds read issues in the realmedia
demuxer (rmdemux, rmutils, rademux), covering both CVE-2026-53703
and CVE-2026-53704.

CVE: CVE-2026-53703
CVE: CVE-2026-53704
Upstream patches:
 - https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/11832.patch
Resolves: RHEL-184437
Resolves: RHEL-184465

This commit was backported by Ymir, a Red Hat Enterprise Linux software maintenance AI agent.

Assisted-by: Ymir
2026-07-29 15:50:46 +02:00
.gitignore 1.22.12 2024-08-27 12:50:04 +02:00
0001-asfdemux-Error-out-on-files-with-more-than-32-stream.patch Add patch for CVE-2026-2920, CVE-2026-2922 2026-03-27 13:17:03 +01:00
0002-rmdemux-Check-if-new-video-fragment-overflows-the-fr.patch Add patch for CVE-2026-2920, CVE-2026-2922 2026-03-27 13:17:03 +01:00
0003-rmdemux-Avoid-integer-overflow-when-checking-if-enou.patch Add patch for CVE-2026-2920, CVE-2026-2922 2026-03-27 13:17:03 +01:00
0004-CVE-2026-53704.patch Fix OOB reads in realmedia demuxer (CVE-2026-53703, CVE-2026-53704) 2026-07-29 15:50:46 +02:00
gating.yaml enabling gating for el9 2021-06-16 13:25:41 +02:00
gstreamer1-plugins-ugly-free.spec Fix OOB reads in realmedia demuxer (CVE-2026-53703, CVE-2026-53704) 2026-07-29 15:50:46 +02:00
sources 1.22.12 2024-08-27 12:50:04 +02:00