USN-8798-1: GStreamer Good Plugins vulnerabilities
Ubuntu patches four GStreamer Good Plugins parsing flaws in MRF, PNG, and RTP handling that could allow remote code execution.
USN-8798-1 fixes incorrect parsing of certain MRF files (CVE-2026-18295, CVE-2026-18296) and PNG files (CVE-2026-18298) in GStreamer Good Plugins, where a remote attacker could possibly execute arbitrary code. DongHyeon Hwang discovered incorrect handling of certain RTP packets (CVE-2026-18299), also enabling possible remote code execution. Ubuntu users should update affected packages.
- Four CVEs in GStreamer Good Plugins, all potentially allowing remote code execution
- Flaws span MRF and PNG file parsing plus RTP packet handling
- CVE-2026-18299 credited to researcher DongHyeon Hwang
Vulnerabilities mentionedAll →
- CVE-2026-182987.8<1%GStreamer PNG File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerabilitypublished · gstreamer gstreamer+3 related
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
CVE-2026-18298+3 related CVEs |
It was discovered that GStreamer Good Plugins incorrectly parsed certain MRF files. A remote attacker could possibly use this issue to execute arbitrary code. (CVE-2026-18295, CVE-2026-18296) It was discovered that GStreamer Good Plugins incorrectly parsed certain PNG files. A remote attacker could possibly use this issue to execute arbitrary code. (CVE-2026-18298) DongHyeon Hwang discovered that GStreamer Good Plugins incorrectly handled certain RTP packets. A remote attacker could possibly use this issue to execute arbitrary code. (CVE-2026-18299)
This source does not provide full text. Read it at ubuntu.com.