A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS Summary: Several security issues were fixed in GStreamer Bad Plugins. Software Description: - gst-plugins-bad1.0: GStreamer plugins Details: It was discovered that GStreamer Bad Plugins incorrectly handled parsing H.266/VVC picture partition data. An attacker could use this issue to cause GStreamer Bad Plugins to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2026-53701) It was discovered that GStreamer Bad Plugins incorrectly handled parsing H.265 buffering period metadata. An attacker could use this issue to cause GStreamer Bad Plugins to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2026-53702)
The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS gstreamer1.0-plugins-bad 1.28.2-1ubuntu1.1 libgstreamer-plugins-bad1.0-0 1.28.2-1ubuntu1.1 In general, a standard system update will make all the necessary changes.
https://ubuntu.com/security/notices/USN-8446-1
CVE-2026-53701, CVE-2026-53702
https://launchpad.net/ubuntu/+source/gst-plugins-bad1.0/1.28.2-1ubuntu1.1
Get the latest Linux and open source security news straight to your inbox.