Ubuntu alert USN-8446-1 (gst-plugins-bad1.0)
| From: | noreply+usn-bot--- via ubuntu-security-announce <ubuntu-security-announce@lists.ubuntu.com> | |
| To: | ubuntu-security-announce@lists.ubuntu.com | |
| Subject: | [USN-8446-1] GStreamer Bad Plugins vulnerabilities | |
| Date: | Wed, 17 Jun 2026 15:01:12 +0000 | |
| Message-ID: | <E1wZrlQ-0005l7-HX@lists.ubuntu.com> | |
| Cc: | noreply+usn-bot@canonical.com |
========================================================================== Ubuntu Security Notice USN-8446-1 June 17, 2026 gst-plugins-bad1.0 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS Summary: Several security issues were fixed in GStreamer Bad Plugins. Software Description: - gst-plugins-bad1.0: GStreamer plugins Details: It was discovered that GStreamer Bad Plugins incorrectly handled parsing H.266/VVC picture partition data. An attacker could use this issue to cause GStreamer Bad Plugins to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2026-53701) It was discovered that GStreamer Bad Plugins incorrectly handled parsing H.265 buffering period metadata. An attacker could use this issue to cause GStreamer Bad Plugins to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2026-53702) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS gstreamer1.0-plugins-bad 1.28.2-1ubuntu1.1 libgstreamer-plugins-bad1.0-0 1.28.2-1ubuntu1.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8446-1 CVE-2026-53701, CVE-2026-53702 Package Information: https://launchpad.net/ubuntu/+source/gst-plugins-bad1.0/1...
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmoytpQACgkQcpJm3tlz hgE5Rg//el+wlOEt+Y9V4q6G9aroyoX/02l6a2XgQ6W0cplYUcWEZ1rxaAUydITI XXoG0XoGn7kUVB/Sg5DUrf2AKR85uT9rzJXFLqsd0XRUmqwLrs/hxhxcy2GeMT2l DzHirgxg74LyXo5yLqgLrOHrThPVAUOGQIemAHkRB5uKOSHJQWhX2LLqpELJ4gGa 5KIvu+U/Bpnqd+E+nxdI2pmLSIMM89HUpuOmgj/b7v/3r84oH3Khao1WxP+PmGeN 1TgPOmAmfhTWxfFKpClTSyJQYCSf85FSanR2pGZgwgyW8zkL2kd7o9HHSFNsnL8R RmtJq0qWOZQVQJfPXZw2DrH4KmNXdyiTmhzpGMvjf/foZRkgTIvSm/sRru9q85u6 aNHdk/6yIxk2ICKDC0iXBWrSAO5zoEsRIv1lmOGllcGUzjX1ZOnTRIt7PNPHGBVu 8pv4baGvoxC9COpXjREzIOPfFE80NwhCDPEE5cw6ENZlPm4tdV+3fM3MPN/y9XDy NaqUyhZXdbjvjlgd0zUy6viuDER+fqCg49w4/4ZbBgf3SlEUYbCmJe7ElEPTltEn /kZzT9e04QQHDAKXUkHlGIj0ZCD+KSwJHjbUz+tsA7C/t1lHLS+o2c6UnaUNEXZN SMw8vzKBvCPgr465EjwBH5XFNx5rvce3z5aakShixdESrsLH+3w= =bfxQ -----END PGP SIGNATURE-----
