Red Hat released Important security updates for gstreamer1-plugins-good to fix multiple remote code execution vulnerabilities in GStreamer affecting Red Hat Enterprise Linux 8, 9, and 10. The flaws include CVE-2026-18295 and CVE-2026-18296, both tied to MRF file parsing, CVE-2026-18298, a heap-based buffer overflow in PNG parsing, and CVE-2026-18299, a use-after-free in the rtpsbcdepay component. Red Hat said the bugs could allow arbitrary code execution in the context of the current process after user interaction, such as opening a malicious file or visiting a crafted page, and noted the issues were tracked by ZDI as ZDI-CAN-29510, ZDI-CAN-29608, ZDI-CAN-29581, and ZDI-CAN-29787.
The fixes were shipped through advisories RHSA-2026:59179 for RHEL 8, RHSA-2026:59152 for RHEL 9, and RHSA-2026:59133 for RHEL 10. Red Hat published updated package builds 1.16.1-7.el8_10.7 for RHEL 8, 1.22.12-7.el9_8.8 for RHEL 9, and 1.26.7-2.el10_2.7 for RHEL 10 across multiple architectures and lifecycle channels. RHEL 10 addresses the PNG and one MRF heap overflow issue, while RHEL 8 and RHEL 9 updates cover the broader set of four GStreamer RCE vulnerabilities.

See real exploitation activity before you spend the cycle.
20 events from the most recent confirmed update back to the earliest known activity.
Amazon Linux published ALAS2-2026-3899 for Amazon Linux 2, updating gstreamer1-plugins-good to version 1.18.4-6. The advisory addresses CVE-2026-18295, an MRF parsing out-of-bounds write that can permit code execution with user interaction, and CVE-2026-18649, a remotely exploitable RTP fragment-buffer memory-exhaustion denial of service flaw.
Amazon Linux published advisory ALAS-2026-3898 for Amazon Linux 2 to address CVE-2026-18649 in GStreamer Good Plugins packages. The remotely exploitable flaw can cause high-impact denial of service through memory exhaustion, and exploits were reported as available.
Amazon Linux published ALAS2023-2026-2121 for Amazon Linux 2023, updating gstreamer1-plugins-good to address CVE-2026-18295 and CVE-2026-18649. CVE-2026-18649 can allow unauthenticated remote attackers to exhaust process memory via indefinitely fragmented RTP streams, causing denial of service.
On 2026-08-28, Miracle Linux published security update AXSA-2026-1684 for Miracle Linux 9, updating gstreamer1-plugins-good and gstreamer1-plugins-good-gtk. The advisory addresses CVE-2026-18295, CVE-2026-18296, CVE-2026-18298, and CVE-2026-18299; no known exploits were reported.
On 2026-08-27, Miracle Linux published advisory AXSA-2026-1677, updating gstreamer1-plugins-good and gstreamer1-plugins-good-gtk packages for Miracle Linux 8. The advisory addresses CVE-2026-18295, CVE-2026-18296, CVE-2026-18298, and CVE-2026-18299; no known exploits were reported.
On 2026-08-26, Red Hat issued RHSA-2026:59972 for Red Hat Enterprise Linux 10 to update gstreamer1-plugins-good and address CVE-2026-18299, a use-after-free flaw in GStreamer's rtpsbcdepay component. Red Hat rated the update Important; the advisory stated that no known exploits were available.
On 2026-08-26, Oracle Linux published ELSA-2026-59972 for Oracle Linux 10, updating gstreamer1-plugins-good and gstreamer1-plugins-good-gtk to address CVE-2026-18299. The vulnerability requires local access and user interaction, and the advisory listed no known exploits.
On 2026-08-26, AlmaLinux published advisory ALSA-2026:59972 for AlmaLinux 10, updating affected gstreamer1-plugins-good and gstreamer1-plugins-good-gtk packages to address CVE-2026-18299. The update applies across multiple AlmaLinux 10 repositories, including AppStream, BaseOS, HighAvailability, and SAP-related repositories.
On 2026-08-26, Rocky Linux published RLSA-2026:59972 for Rocky Linux 10 to address CVE-2026-18299 in GStreamer Good Plugins packages, including gstreamer1-plugins-good-gtk and related debug packages. The flaw requires local access and user interaction, and no known exploits were reported.
On 2026-08-25, Rocky Linux published RLSA-2026:59179 for Rocky Linux 8, addressing CVE-2026-18295, CVE-2026-18296, CVE-2026-18298, and CVE-2026-18299 in gstreamer1-plugins-good packages. The advisory directs affected users to update packages to remediate MRF and PNG parsing buffer overflows and an rtpsbcdepay use-after-free flaw.
On 2026-08-25, Rocky Linux published security advisory RLSA-2026:59133 for Rocky Linux 10 covering gstreamer1-plugins-good packages. The advisory addresses CVE-2026-18296 and CVE-2026-18298 and lists affected packages including gstreamer1-plugins-good, gstreamer1-plugins-good-gtk, and related debug packages.
Rocky Linux published security advisory RLSA-2026:59152 for Rocky Linux 9, warning that affected gstreamer1-plugins-good packages contain CVE-2026-18295, CVE-2026-18296, CVE-2026-18298, and CVE-2026-18299. The advisory directs users to update packages to address heap-based buffer overflows in MRF and PNG parsing and a use-after-free flaw in rtpsbcdepay.
On 2026-08-24, AlmaLinux published ALSA-2026:59133 for AlmaLinux 10, updating gstreamer1-plugins-good and gstreamer1-plugins-good-gtk. The advisory addresses CVE-2026-18296 and CVE-2026-18298.
On 2026-08-24, AlmaLinux published ALSA-2026:59152 for AlmaLinux 9, updating gstreamer1-plugins-good and gstreamer1-plugins-good-gtk. The advisory addresses CVE-2026-18295, CVE-2026-18296, CVE-2026-18298, and CVE-2026-18299.
On 2026-08-24, Oracle published ELSA-2026-59152 for Oracle Linux 9, updating gstreamer1-plugins-good and gstreamer1-plugins-good-gtk. The advisory addresses CVE-2026-18295, CVE-2026-18296, CVE-2026-18298, and CVE-2026-18299.
On 2026-08-24, Oracle Linux published ELSA-2026-59179 for Oracle Linux 8, updating gstreamer1-plugins-good and gstreamer1-plugins-good-gtk packages. The advisory addresses CVE-2026-18295, CVE-2026-18296, CVE-2026-18298, and CVE-2026-18299.
On 2026-08-24, Red Hat published RHSA-2026:59179 for Red Hat Enterprise Linux 8, releasing gstreamer1-plugins-good-1.16.1-7.el8_10.7. The advisory fixes CVE-2026-18295, CVE-2026-18296, CVE-2026-18298, and CVE-2026-18299 across supported RHEL 8 architectures and Extended Life Cycle 8.10 variants.
On 2026-08-24, Red Hat published RHSA-2026:59152 for Red Hat Enterprise Linux 9, releasing gstreamer1-plugins-good-1.22.12-7.el9_8.8. The advisory addresses CVE-2026-18295, CVE-2026-18296, CVE-2026-18298, and CVE-2026-18299, covering MRF parsing flaws, a PNG parsing heap overflow, and a use-after-free in rtpsbcdepay.
On 2026-08-24, Red Hat published RHSA-2026:59133 for Red Hat Enterprise Linux 10, releasing gstreamer1-plugins-good-1.26.7-2.el10_2.7. The advisory fixes CVE-2026-18296, a heap-based buffer overflow in MRF parsing, and CVE-2026-18298, a heap-based buffer overflow in PNG parsing.
Unity Linux published security advisory UTSA-2026-101049 to address CVE-2026-59691. The patch was published in August 2026; the vulnerability had been publicly disclosed in July 2026, and the advisory reported no known exploits.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
25 references tracked. Mallory keeps watching after this page renders.
tenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceexplore.alas.aws.amazon.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.