Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Fedora 42 Update for mingw-gstreamer1-plugins-bad Resolves Major Code Flaws

fedora
Calendar Grey April 5, 2026
Dist Fedora Esm H88
Update to gstreamer-1.26.11 resolves multiple remote code execution risks in Fedora 42.
Update to gstreamer-1.26.11.

Summary

GStreamer is a streaming media framework, based on graphs of elements which

operate on media data.

This package contains plug-ins that aren't tested

well enough, or the code is not of good enough quality.

Update Information:

Update to gstreamer-1.26.11.

Change Log

* Fri Mar 27 2026 Sandro Mani - 1.26.11-1 - Update to 1.26.11

References


[ 1 ] Bug #2447936 - CVE-2026-2920 mingw-gstreamer1: GStreamer: Arbitrary code execution via ASF file processing [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2447936 [ 2 ] Bug #2448013 - CVE-2026-3084 mingw-gstreamer1: GStreamer: Remote Code Execution via integer underflow in H.266 Codec Parser [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2448013 [ 3 ] Bug #2448019 - CVE-2026-2922 mingw-gstreamer1: GStreamer: Remote Code Execution via out-of-bounds write in RealMedia Demuxer [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2448019 [ 4 ] Bug #2448020 - CVE-2026-2921 mingw-gstreamer1: GStreamer: Arbitrary code execution via RIFF palette integer overflow in AVI file handling [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2448020 [ 5 ] Bug #2448021 - CVE-2026-2923 mingw-gstreamer1: GStreamer: Remote Code Execution via out-of-bounds write in DVB Subtitles handling [fedora-all] https://bug...

Read the Full Advisory

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-3cc99e7d09' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: mingw-gstreamer1-plugins-bad-free
Product: Fedora 42
Version: 1.26.11
Release: 1.fc42
Summary: Cross compiled GStreamer1 plug-ins "bad"

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here