Red Hat released Important security updates for gstreamer1-plugins-base on Red Hat Enterprise Linux 8 and 10 to remediate CVE-2026-18297, a stack-based buffer overflow in GStreamer’s OGG-file parser. Improper validation of attacker-controlled data length before copying it into a stack buffer can allow arbitrary code execution in the context of the application processing the file.
Exploitation requires user interaction, such as opening a malicious OGG file or visiting a page that causes vulnerable GStreamer components to parse one; no public exploits were reported. Organizations should deploy RHSA-2026:59487 on RHEL 8, which supplies gstreamer1-plugins-base-1.16.1-6.el8_10.1, and RHSA-2026:59097 on RHEL 10, which supplies 1.26.7-2.el10_2.1, across affected x86_64, aarch64, ppc64le, and s390x systems.

See real exploitation activity before you spend the cycle.
6 events from the most recent confirmed update back to the earliest known activity.
Miracle Linux published advisory AXSA-2026-1683 for Miracle Linux 8, addressing CVE-2026-18297 in gstreamer1-plugins-base and gstreamer1-plugins-base-devel. The advisory provides an official fix and states that no known exploits are available.
Rocky Linux published security advisory RLSA-2026-59487 for Rocky Linux 8, addressing CVE-2026-18297 in gstreamer1-plugins-base packages, including development and debug variants. The advisory states that no known exploits were available.
Oracle Linux published security advisory ELSA-2026-59487 for Oracle Linux 8, addressing CVE-2026-18297 in gstreamer1-plugins-base and gstreamer1-plugins-base-devel. The assessment reported no known exploits.
Red Hat issued Important-rated RHSA-2026:59487 for RHEL 8 and applicable RHEL 8.10 Extended Life Cycle systems, addressing CVE-2026-18297. The update supplied gstreamer1-plugins-base version 1.16.1-6.el8_10.1.
Red Hat issued Important-rated RHSA-2026:59097 for RHEL 10, fixing CVE-2026-18297 in gstreamer1-plugins-base. Fixed version 1.26.7-2.el10_2.1 was provided for x86_64, s390x, ppc64le, and aarch64 deployments.
CVE-2026-18297, a GStreamer OGG-file parsing buffer overflow that can allow arbitrary code execution, was published. The flaw is categorized as CWE-120 and exploitation requires a victim to open a malicious OGG file or visit a malicious page.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
7 references tracked. Mallory keeps watching after this page renders.
tenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourceaccess.redhat.com
Open sourcetenable.com
Open sourcebugzilla.redhat.com
Open sourceaccess.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.