OESA-2026-3580

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2026-3580
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2026-3580.json
JSON Data
https://api.osv.dev/v1/vulns/OESA-2026-3580
Upstream
  • CVE-2026-14935
  • CVE-2026-59692
Published
2026-08-30T04:18:32Z
Modified
2026-08-30T04:32:43.343260452Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
gstreamer1-plugins-bad-free security update
Details

GStreamer is a pipeline-based multi media framework that links together a wide variety of media processing systems to complete complex workflows, based on graphs of filters which operate on media data. This package contains plug-ins that are not tested well enough yet, or the code is not of good enough quality.

Security Fix(es):

A logic vulnerability was found in GStreamer's webrtcbin component. The checksdp_crypto() function contains an inverted boolean condition that causes it to accept remote SDP offers or answers that lack the required a=fingerprint attribute, while incorrectly rejecting those that include it. An attacker with the ability to intercept and modify WebRTC signaling messages could exploit this to bypass the SDP-level DTLS certificate fingerprint binding, weakening defenses against man-in-the-middle attacks on media streams.(CVE-2026-14935)

A stack buffer overflow vulnerability was found in GStreamer's DTLS plugin. During a DTLS handshake, the peer certificate Subject Distinguished Name is printed into a fixed-size 2048-byte stack buffer without bounds checking. A remote unauthenticated attacker can send a certificate with an oversized Subject DN that exceeds the buffer, causing a stack buffer overflow and process crash, resulting in denial of service.(CVE-2026-59692)

Database specific
{
    "severity": "High"
}
References

Affected packages

openEuler:20.03-LTS-SP4
gstreamer1-plugins-bad-free

Package

Name
gstreamer1-plugins-bad-free
Purl
pkg:rpm/openEuler/gstreamer1-plugins-bad-free&distro=openEuler-20.03-LTS-SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.16.2-9.oe2003sp4

Ecosystem specific

{
    "x86_64": [
        "gstreamer1-plugins-bad-free-1.16.2-9.oe2003sp4.x86_64.rpm",
        "gstreamer1-plugins-bad-free-debuginfo-1.16.2-9.oe2003sp4.x86_64.rpm",
        "gstreamer1-plugins-bad-free-debugsource-1.16.2-9.oe2003sp4.x86_64.rpm",
        "gstreamer1-plugins-bad-free-devel-1.16.2-9.oe2003sp4.x86_64.rpm"
    ],
    "aarch64": [
        "gstreamer1-plugins-bad-free-1.16.2-9.oe2003sp4.aarch64.rpm",
        "gstreamer1-plugins-bad-free-debuginfo-1.16.2-9.oe2003sp4.aarch64.rpm",
        "gstreamer1-plugins-bad-free-debugsource-1.16.2-9.oe2003sp4.aarch64.rpm",
        "gstreamer1-plugins-bad-free-devel-1.16.2-9.oe2003sp4.aarch64.rpm"
    ],
    "src": [
        "gstreamer1-plugins-bad-free-1.16.2-9.oe2003sp4.src.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-3580.json"
openEuler:22.03-LTS-SP4
gstreamer1-plugins-bad-free

Package

Name
gstreamer1-plugins-bad-free
Purl
pkg:rpm/openEuler/gstreamer1-plugins-bad-free&distro=openEuler-22.03-LTS-SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.16.2-18.oe2203sp4

Ecosystem specific

{
    "x86_64": [
        "gstreamer1-plugins-bad-free-1.16.2-18.oe2203sp4.x86_64.rpm",
        "gstreamer1-plugins-bad-free-debuginfo-1.16.2-18.oe2203sp4.x86_64.rpm",
        "gstreamer1-plugins-bad-free-debugsource-1.16.2-18.oe2203sp4.x86_64.rpm",
        "gstreamer1-plugins-bad-free-devel-1.16.2-18.oe2203sp4.x86_64.rpm"
    ],
    "aarch64": [
        "gstreamer1-plugins-bad-free-1.16.2-18.oe2203sp4.aarch64.rpm",
        "gstreamer1-plugins-bad-free-debuginfo-1.16.2-18.oe2203sp4.aarch64.rpm",
        "gstreamer1-plugins-bad-free-debugsource-1.16.2-18.oe2203sp4.aarch64.rpm",
        "gstreamer1-plugins-bad-free-devel-1.16.2-18.oe2203sp4.aarch64.rpm"
    ],
    "src": [
        "gstreamer1-plugins-bad-free-1.16.2-18.oe2203sp4.src.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-3580.json"
openEuler:24.03-LTS-SP1
gstreamer1-plugins-bad-free

Package

Name
gstreamer1-plugins-bad-free
Purl
pkg:rpm/openEuler/gstreamer1-plugins-bad-free&distro=openEuler-24.03-LTS-SP1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.16.2-18.oe2403sp1

Ecosystem specific

{
    "x86_64": [
        "gstreamer1-plugins-bad-free-1.16.2-18.oe2403sp1.x86_64.rpm",
        "gstreamer1-plugins-bad-free-debuginfo-1.16.2-18.oe2403sp1.x86_64.rpm",
        "gstreamer1-plugins-bad-free-debugsource-1.16.2-18.oe2403sp1.x86_64.rpm",
        "gstreamer1-plugins-bad-free-devel-1.16.2-18.oe2403sp1.x86_64.rpm"
    ],
    "aarch64": [
        "gstreamer1-plugins-bad-free-1.16.2-18.oe2403sp1.aarch64.rpm",
        "gstreamer1-plugins-bad-free-debuginfo-1.16.2-18.oe2403sp1.aarch64.rpm",
        "gstreamer1-plugins-bad-free-debugsource-1.16.2-18.oe2403sp1.aarch64.rpm",
        "gstreamer1-plugins-bad-free-devel-1.16.2-18.oe2403sp1.aarch64.rpm"
    ],
    "src": [
        "gstreamer1-plugins-bad-free-1.16.2-18.oe2403sp1.src.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-3580.json"
openEuler:24.03-LTS-SP3
gstreamer1-plugins-bad-free

Package

Name
gstreamer1-plugins-bad-free
Purl
pkg:rpm/openEuler/gstreamer1-plugins-bad-free&distro=openEuler-24.03-LTS-SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.16.2-18.oe2403sp3

Ecosystem specific

{
    "x86_64": [
        "gstreamer1-plugins-bad-free-1.16.2-18.oe2403sp3.x86_64.rpm",
        "gstreamer1-plugins-bad-free-debuginfo-1.16.2-18.oe2403sp3.x86_64.rpm",
        "gstreamer1-plugins-bad-free-debugsource-1.16.2-18.oe2403sp3.x86_64.rpm",
        "gstreamer1-plugins-bad-free-devel-1.16.2-18.oe2403sp3.x86_64.rpm"
    ],
    "aarch64": [
        "gstreamer1-plugins-bad-free-1.16.2-18.oe2403sp3.aarch64.rpm",
        "gstreamer1-plugins-bad-free-debuginfo-1.16.2-18.oe2403sp3.aarch64.rpm",
        "gstreamer1-plugins-bad-free-debugsource-1.16.2-18.oe2403sp3.aarch64.rpm",
        "gstreamer1-plugins-bad-free-devel-1.16.2-18.oe2403sp3.aarch64.rpm"
    ],
    "src": [
        "gstreamer1-plugins-bad-free-1.16.2-18.oe2403sp3.src.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-3580.json"
openEuler:24.03-LTS-SP4
gstreamer1-plugins-bad-free

Package

Name
gstreamer1-plugins-bad-free
Purl
pkg:rpm/openEuler/gstreamer1-plugins-bad-free&distro=openEuler-24.03-LTS-SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.16.2-18.oe2403sp4

Ecosystem specific

{
    "x86_64": [
        "gstreamer1-plugins-bad-free-1.16.2-18.oe2403sp4.x86_64.rpm",
        "gstreamer1-plugins-bad-free-debuginfo-1.16.2-18.oe2403sp4.x86_64.rpm",
        "gstreamer1-plugins-bad-free-debugsource-1.16.2-18.oe2403sp4.x86_64.rpm",
        "gstreamer1-plugins-bad-free-devel-1.16.2-18.oe2403sp4.x86_64.rpm"
    ],
    "aarch64": [
        "gstreamer1-plugins-bad-free-1.16.2-18.oe2403sp4.aarch64.rpm",
        "gstreamer1-plugins-bad-free-debuginfo-1.16.2-18.oe2403sp4.aarch64.rpm",
        "gstreamer1-plugins-bad-free-debugsource-1.16.2-18.oe2403sp4.aarch64.rpm",
        "gstreamer1-plugins-bad-free-devel-1.16.2-18.oe2403sp4.aarch64.rpm"
    ],
    "src": [
        "gstreamer1-plugins-bad-free-1.16.2-18.oe2403sp4.src.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-3580.json"