The vendor explicitly identifies these products or versions as containing the fix.
- gstreamer1-plugins-good-0:1.26.7-2.el10_2.2.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
- gstreamer1-plugins-good-0:1.26.7-2.el10_2.2.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 10)
- gstreamer1-plugins-good-0:1.26.7-2.el10_2.2.s390x as a component of Red Hat Enterprise Linux AppStream (v. 10)
- gstreamer1-plugins-good-0:1.26.7-2.el10_2.2.src as a component of Red Hat Enterprise Linux AppStream (v. 10)
- gstreamer1-plugins-good-0:1.26.7-2.el10_2.2.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
- gstreamer1-plugins-good-debuginfo-0:1.26.7-2.el10_2.2.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
- gstreamer1-plugins-good-debuginfo-0:1.26.7-2.el10_2.2.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 10)
- gstreamer1-plugins-good-debuginfo-0:1.26.7-2.el10_2.2.s390x as a component of Red Hat Enterprise Linux AppStream (v. 10)
- gstreamer1-plugins-good-debuginfo-0:1.26.7-2.el10_2.2.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
- gstreamer1-plugins-good-debugsource-0:1.26.7-2.el10_2.2.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
- gstreamer1-plugins-good-debugsource-0:1.26.7-2.el10_2.2.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 10)
- gstreamer1-plugins-good-debugsource-0:1.26.7-2.el10_2.2.s390x as a component of Red Hat Enterprise Linux AppStream (v. 10)
- Summary
- A stack-based buffer overflow in GStreamer's qtdemux component allows attackers to execute arbitrary code via specially crafted input. This occurs due to insufficient data length validation when parsing UncompressedFrameConfigBox structures.
- Remediation
- For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
