Ubuntu patches GStreamer flaws that could allow code execution
Ubuntu’s 21 September 2026 notices fix GStreamer flaws in OGG, MRF, PNG, and RTP handling that could allow remote code execution.
On 2026-09-21, Ubuntu published two security notices for GStreamer plugins that could let a remote attacker execute arbitrary code. USN-8797-1, issued at 18:05 UTC, says GStreamer Base Plugins incorrectly handled certain OGG media files; opening a specially crafted file could allow code execution, and the notice cites no CVE and does not report exploitation in the wild. About 27 minutes later, USN-8798-1 addressed four GStreamer Good Plugins issues: incorrect parsing of MRF files (CVE-2026-18295 and CVE-2026-18296), incorrect parsing of PNG files (CVE-2026-18298), and incorrect handling of RTP packets (CVE-2026-18299), the last credited to DongHyeon Hwang. Each of those flaws could possibly allow remote code execution, and Ubuntu advised users to update affected packages. The two notices do not conflict; earlier coverage had treated the RTP finding’s details as unavailable because the source text was truncated.
- USN-8797-1 (2026-09-21T18:05:39Z): GStreamer Base Plugins incorrectly handled certain OGG media files; a specially crafted file could allow remote arbitrary code execution.
- USN-8797-1 cites no CVE and does not report exploitation in the wild.
- USN-8798-1 (2026-09-21T18:32:49Z) covers four GStreamer Good Plugins flaws, each potentially allowing remote code execution.
- CVE-2026-18295 and CVE-2026-18296: incorrect parsing of certain MRF files.
- CVE-2026-18298: incorrect parsing of certain PNG files.
- CVE-2026-18299: incorrect handling of certain RTP packets, credited to DongHyeon Hwang.
- Ubuntu advised users to update affected packages; neither notice included exploit code or affected-version specifics.
Coverage timelineoldest first · each row is one article
- · 5d agoUSN-8797-1: GStreamer Base Plugins vulnerability
Ubuntu Security Notices· 34
Ubuntu warned that crafted OGG files could let attackers execute code via GStreamer Base Plugins.
- · 5d agoUSN-8798-1: GStreamer Good Plugins vulnerabilities
Ubuntu Security Notices· 25
Ubuntu patches four GStreamer Good Plugins parsing flaws in MRF, PNG, and RTP handling that could allow remote code execution.
Vulnerabilities in this storyAll →
- CVE-2026-182987.8<1%GStreamer PNG File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerabilitypublished · gstreamer gstreamer+3 related
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
CVE-2026-18298+3 related CVEs |