Red Hat released an Important update for gstreamer1-plugins-good on Red Hat Enterprise Linux 8, addressing four vulnerabilities—CVE-2026-18295, CVE-2026-18296, CVE-2026-18298, and CVE-2026-18299—that could permit remote code execution when vulnerable media content is processed. The defects affect MRF parsing, including a heap-based buffer overflow, PNG parsing with another heap-based buffer overflow, and a use-after-free condition in rtpsbcdepay; memory-corruption flaws of this type can cause application crashes or enable execution of attacker-controlled code.
The fixed RHEL 8 packages are version 1.16.1-7.el8_10.7, released for multiple architectures and RHEL 8.10 Extended Life Cycle variants. AlmaLinux 8 issued the corresponding ALSA-2026:59179 update for gstreamer1-plugins-good and gstreamer1-plugins-good-gtk; Nessus reports high potential confidentiality, integrity, and availability impact, though no known public exploits were available. Organizations should identify affected local packages and apply the vendor updates promptly, especially on systems that process untrusted audio, video, image, or RTP media streams.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
AlmaLinux published security advisory ALSA-2026:59179 for AlmaLinux 8 packages gstreamer1-plugins-good and gstreamer1-plugins-good-gtk, addressing the same four GStreamer CVEs. The associated Nessus entry reported no known exploits available.
Red Hat issued Important advisory RHSA-2026:59179 for RHEL 8, releasing gstreamer1-plugins-good version 1.16.1-7.el8_10.7. The update fixes CVE-2026-18295, CVE-2026-18296, CVE-2026-18298, and CVE-2026-18299, including heap overflows and a use-after-free that could permit remote code execution.
Four GStreamer vulnerabilities—CVE-2026-18295, CVE-2026-18296, CVE-2026-18298, and CVE-2026-18299—were published. They affect MRF and PNG parsing and the rtpsbcdepay component, with potential remote code execution impact.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
4 references tracked. Mallory keeps watching after this page renders.
tenable.com
Open sourceaccess.redhat.com
Open sourcecwe.mitre.org
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.