[El-errata] ELSA-2026-59152 Important: Oracle Linux 9 gstreamer1-plugins-good security update

Errata Announcements for Oracle Linux el-errata at oss.oracle.com
Wed Aug 26 09:22:50 UTC 2026


Oracle Linux Security Advisory ELSA-2026-59152

http://linux.oracle.com/errata/ELSA-2026-59152.html

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

x86_64:
gstreamer1-plugins-good-1.22.12-7.el9_8.8.i686.rpm
gstreamer1-plugins-good-1.22.12-7.el9_8.8.x86_64.rpm
gstreamer1-plugins-good-gtk-1.22.12-7.el9_8.8.i686.rpm
gstreamer1-plugins-good-gtk-1.22.12-7.el9_8.8.x86_64.rpm

aarch64:
gstreamer1-plugins-good-1.22.12-7.el9_8.8.aarch64.rpm
gstreamer1-plugins-good-gtk-1.22.12-7.el9_8.8.aarch64.rpm


SRPMS:
http://oss.oracle.com/ol9/SRPMS-updates/gstreamer1-plugins-good-1.22.12-7.el9_8.8.src.rpm

Related CVEs:

CVE-2026-18295
CVE-2026-18296
CVE-2026-18298
CVE-2026-18299




Description of changes:

[1.22.12-7.8]
- Fix CVE-2026-18299: Use-After-Free in rtpsbcdepay
  Resolves: RHEL-246619

[1.22.12-7.7]
- Fix CVE-2026-18296: size validation in qtmoovrecover MRF parsing
  Resolves: RHEL-246558

[1.22.12-7.6]
- Fix CVE-2026-18298 in gdkpixbufdec element
  Resolves: RHEL-246572

[1.22.12-7.5]
- Fix CVE-2026-18295: validate box sizes in qtmoovrecover to prevent
  heap buffer overflow (same upstream fix as CVE-2026-18296)
  Resolves: RHEL-246380




More information about the El-errata mailing list