GStreamer gst-plugins-bad VA JPEG decoder是GStreamer组织的一个硬件加速解码组件。 GStreamer gst-plugins-bad VA JPEG decoder存在缓冲区错误漏洞,该漏洞源于JPEG解析器从位流中读取段长度值时未根据可用数据进行验证,可能导致远程攻击者诱骗用户打开特制JPEG文件,造成下游解析超出提供输入缓冲区,导致崩溃或潜在信息泄露。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | 0:1.26.7-2.el10_2.4< * |
unaffected |
| Red Hat | Red Hat Enterprise Linux 10.0 Extended Update Support | 0:1.24.11-3.el10_0.4< * |
unaffected |
| Red Hat | Red Hat Enterprise Linux 6 | any |
unknown |
| Red Hat | Red Hat Enterprise Linux 7 | any |
unaffected |
any |
unaffected | ||
| Red Hat | Red Hat Enterprise Linux 8 | any |
unaffected |
| Red Hat | Red Hat Enterprise Linux 9 | 0:1.22.12-7.el9_8.1< * |
unaffected |
| Red Hat | Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions | 0:1.22.1-6.el9_4.4< * |
unaffected |
| Red Hat | Red Hat Enterprise Linux 9.6 Extended Update Support | 0:1.22.12-5.el9_6.4< * |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | 0:1.26.7-2.el10_2.4 ~ * |
cpe:/o:redhat:enterprise_linux:10.2
|
|
| Red Hat | Red Hat Enterprise Linux 10.0 Extended Update Support | 0:1.24.11-3.el10_0.4 ~ * |
cpe:/o:redhat:enterprise_linux_eus:10.0
|
|
| Red Hat | Red Hat Enterprise Linux 9 | 0:1.22.12-7.el9_8.1 ~ * |
cpe:/a:redhat:enterprise_linux:9::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions | 0:1.22.1-6.el9_4.4 ~ * |
cpe:/a:redhat:rhel_e4s:9.4::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 9.6 Extended Update Support | 0:1.22.12-5.el9_6.4 ~ * |
cpe:/a:redhat:rhel_eus:9.6::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-52720 | 8.8 HIGH | Gstreamer1-plugins-bad-free: gstreamer: heap buffer overflow via crafted vnc server rectan |
| CVE-2026-53705 | 7.6 HIGH | Gstreamer1-plugins-good: gstreamer: heap buffer overflow in wavpack decoder via integer ov |
| CVE-2026-52722 | 7.1 HIGH | Gstreamer1-plugins-bad-free: gstreamer: signed integer overflow in vmnc decoder cursor pay |
| CVE-2026-53703 | 7.1 HIGH | Gstreamer1-plugins-ugly-free: gstreamer: out-of-bounds read in realmedia demuxer audio str |
| CVE-2026-53704 | 7.1 HIGH | Gstreamer1-plugins-ugly-free: gstreamer: out-of-bounds read in realmedia demuxer fileinfo |
| CVE-2026-52718 | 6.5 MEDIUM | Gstreamer1-plugins-bad-free: gstreamer: denial of service via av1 tile_list_obu parser byt |
| CVE-2026-52721 | 5.3 MEDIUM | Gstreamer1-plugins-bad-free: gstreamer: multiple out-of-bounds reads in pcapparse ipv4/tcp |
| CVE-2026-44188 | 5.3 MEDIUM | Ansible-lightspeed: ansible lightspeed: session hijacking and unauthorized data access due |
No comments yet