ZeroHour
Ubuntu Security Noticespublished ()ingested
Part of a story covered by 19 sources: “Ubuntu roundup (2026-09-16 to 2026-09-18): ten USNs fix 16 CVEs, including Rclone unauthenticated command execution and Arm kernel TLB race” — merged summary and timeline →

USN-8778-1: GStreamer Good Plugins vulnerability

lowAdvisoryimportance 20
AI summary · glm-5.3-flash

Ubuntu issued USN-8778-1 fixing a GStreamer Good Plugins flaw that lets remote attackers cause resource exhaustion and denial of service via fragmented RTP packets.

Ubuntu Security Notice USN-8778-1 addresses a flaw in GStreamer Good Plugins, which failed to limit the size of reassembly buffers when processing fragmented RTP packets. A remote attacker could exploit this to make GStreamer consume excessive resources, resulting in a denial of service. The notice provides patched packages for supported Ubuntu releases; no CVE id is listed in the text and no exploitation is reported.

  • GStreamer Good Plugins did not limit reassembly buffer size for fragmented RTP packets.
  • Remote attacker could trigger excessive resource consumption and denial of service.
  • Ubuntu has released patched packages via USN-8778-1.
Full article

It was discovered that GStreamer Good Plugins did not limit the size of reassembly buffers when processing fragmented RTP packets. A remote attacker could possibly use this issue to cause GStreamer Good Plugins to use excessive resources, leading to a denial of service.

This source does not provide full text. Read it at ubuntu.com.