EudorIACyber Intelligence
Operational monitoring Newsletter IT EN
← Back to intelligence
Technical advisory

USN-8798-1: GStreamer Good Plugins vulnerabilities

Official source
EudorIA operational summary

What it means

Priority 70/100

GStreamer Good Plugins presenta vulnerabilità di parsing di file MRF, PNG e gestione di pacchetti RTP, che potrebbero permettere l'esecuzione di codice arbitrario da parte di un attaccante remoto. Le vulnerabilità sono state corrette con aggiornamenti di pacchetti specifici. Non è confermato un sfruttamento attivo in rete.

Why it matters

Le PMI italiane che utilizzano GStreamer Good Plugins potrebbero essere esposte a attacchi remoti con esecuzione di codice, minacciando la sicurezza e la continuità operativa. L'aggiornamento dei pacchetti è fondamentale per ridurre il rischio.

Potential operational benefits

  • Riduzione della superficie esposta a vulnerabilità
  • Miglioramento della protezione contro attacchi remoti
  • Riduzione del rischio di esecuzione di codice non autorizzato
  • Miglioramento della capacità di rilevamento e risposta agli incidenti
Indications to confirm against the customer's technical and organisational perimeter.
Relevant controlsPatch managementFirewall NGFW / IPSMonitoraggio / SIEMSegmentazione di reteBackup & DR
AudienceITSOCCISO
Information centre

Translation in progress

Ubuntu Security

The official content is available in the original language. The Italian version will be published once automated checks are complete.

Text acquired from the source

It was discovered that GStreamer Good Plugins incorrectly parsed certain MRF files. A remote attacker could possibly use this issue to execute arbitrary code. (CVE-2026-18295, CVE-2026-18296) It was discovered that GStreamer Good Plugins incorrectly parsed certain PNG files. A remote attacker could possibly use this issue to execute arbitrary code. (CVE-2026-18298) DongHyeon Hwang discovered that GStreamer Good Plugins incorrectly handled certain RTP packets. A remote attacker could possibly use this issue to execute arbitrary code. (CVE-2026-18299)

Source
Ubuntu Security Notices
Publishing entity
Ubuntu Security
Entity type
vendor security
Area
Global
Original language
en · translation in preparation
Publication
21/09/2026 20:32
MITRE ATT&CK
T1595, T1059.001
CVE
CVE-2026-18295, CVE-2026-18296, CVE-2026-18298, CVE-2026-18299
Technical scope

Affected products and versions

Verification in progress
Information not yet acquired.

The collector will check NVD and the available official vendor advisories.

Open the original source