[CLSA-2026:1786960802] gstreamer1-plugins-bad-free: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2026-08-17 10:00:13 UTC
Description:
- CVE-2026-52722: fix signed integer overflow in VMnc decoder cursor payload size arithmetic that bypassed a rectangle length check - CVE-2026-52720: fix heap buffer overflow in librfb by validating framebuffer update rectangle dimensions against the framebuffer size
Updated packages:
  • gstreamer1-plugins-bad-free-1.18.4-6.el9_2.tuxcare.els6.i686.rpm
    sha:313b71b3f162acdd529b062796d47089d9d01e6e1e0e098ed0a23192674aeb10
  • gstreamer1-plugins-bad-free-1.18.4-6.el9_2.tuxcare.els6.x86_64.rpm
    sha:5b8f41701f57cf25dfebf3510d875ac2d5722e2de61bf713606a9eb0df110721
  • gstreamer1-plugins-bad-free-devel-1.18.4-6.el9_2.tuxcare.els6.i686.rpm
    sha:1ee683d80ede48ae1aef896967bf4f707307873ada5780a3d54fa9932003ed0a
  • gstreamer1-plugins-bad-free-devel-1.18.4-6.el9_2.tuxcare.els6.x86_64.rpm
    sha:c47849bd2b6b866cc02c34b572983189bf8f21717a3e2f58c51a92f71644f9b3
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.