Red Hat released multiple Important security advisories for gstreamer1-plugins-bad-free across Red Hat Enterprise Linux 9 and 10, fixing two GStreamer vulnerabilities tracked as CVE-2026-59691 and CVE-2026-59692. The first flaw is a heap out-of-bounds write in rfbsrc/librfb Hextile handling when processing a 16bpp framebuffer, while the second is a stack buffer overflow in openssl_verify_callback tied to a DTLS certificate Subject DN. The advisories cover standard and extended support channels, including RHEL 9.4, 9.6, 9.8, and RHEL 10.0 product variants.
Updated packages were issued for multiple architectures, including x86_64, aarch64, ppc64le, and s390x, with package versions including 1.22.1-6.el9_4.6, 1.22.12-5.el9_6.6, 1.22.12-7.el9_8.3, 1.24.11-3.el10_0.6, and 1.26.7-2.el10_2.6. Affected offerings also include Extended Update Support, Extended Life Cycle, SAP Solutions update services, 4-years-of-updates/support variants, and CodeReady Linux Builder repositories. Red Hat instructed customers to apply the updated packages through standard patching processes to remediate affected systems.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
On 2026-08-13, Red Hat published RHSA-2026:54660, an Important advisory for gstreamer1-plugins-bad-free on Red Hat Enterprise Linux 9.6 Extended Update Support and related channels. The update released version 1.22.12-5.el9_6.6 and remediated CVE-2026-59691 and CVE-2026-59692.
On 2026-08-13, Red Hat published RHSA-2026:54659, an Important advisory for gstreamer1-plugins-bad-free on Red Hat Enterprise Linux 10.0 Extended Update Support and related channels. The update released version 1.24.11-3.el10_0.6 and fixed CVE-2026-59691 and CVE-2026-59692 across multiple architectures.
On 2026-08-13, Red Hat published RHSA-2026:54658, an Important advisory for gstreamer1-plugins-bad-free in RHEL 9.4 offerings including SAP Solutions and Extended Life Cycle channels. The update released version 1.22.1-6.el9_4.6 to fix CVE-2026-59691 and CVE-2026-59692.
On 2026-07-28, Red Hat published RHSA-2026:47180, an Important advisory for gstreamer1-plugins-bad-free on Red Hat Enterprise Linux 10. The update released package version 1.26.7-2.el10_2.6 and addressed CVE-2026-59691 and CVE-2026-59692 for RHEL 10 and related channels.
On 2026-07-28, Red Hat published RHSA-2026:47179, an Important security advisory for gstreamer1-plugins-bad-free on Red Hat Enterprise Linux 9. The update released version 1.22.12-7.el9_8.3 and fixed CVE-2026-59691 and CVE-2026-59692 across multiple RHEL 9 channels and architectures.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.