Red Hat Product Errata RHSA-2026:47718 - Security Advisory Issued: 2026-07-29 Updated: 2026-07-29 RHSA-2026:47718 - Security Advisory Overview Updated Packages Synopsis Important: gstreamer1-plugins-bad-free security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for gstreamer1-plugins-bad-free is now available for Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions and Red Hat Enterprise Linux 8.8 Telecommunications Update Service. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description GStreamer is a streaming media framework based on graphs of filters which operate on media data. The gstreamer1-plugins-bad-free package contains a collection of plug-ins for GStreamer. Security Fix(es): gstreamer1-plugins-bad-free: GStreamer: Heap buffer overflow via crafted VNC server rectangle in librfb (CVE-2026-52720) gstreamer1-plugins-bad-free: GStreamer: Signed integer overflow in VMnc decoder cursor payload handling (CVE-2026-52722) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Life Cycle Long Life 8.8 x86_64 Red Hat Enterprise Linux Server - TUS 8.8 x86_64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.8 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.8 x86_64 Fixes BZ - 2486731 - CVE-2026-52720 gstreamer1-plugins-bad-free: GStreamer: Heap buffer overflow via crafted VNC server rectangle in librfb BZ - 2486733 - CVE-2026-52722 gstreamer1-plugins-bad-free: GStreamer: Signed integer overflow in VMnc decoder cursor payload handling CVEs CVE-2026-52720 CVE-2026-52722 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Life Cycle Long Life 8.8 SRPM gstreamer1-plugins-bad-free-1.16.1-4.el8_8.2.src.rpm SHA-256: 09fba467bc7bca7c917499e5dc53a7c8756af35a2ee9062249549bd7164e5bc9 x86_64 gstreamer1-plugins-bad-free-1.16.1-4.el8_8.2.i686.rpm SHA-256: d1336284eb658bb40d9eee33b921b6f219ec47a4414975b43506c82fa636f86d gstreamer1-plugins-bad-free-1.16.1-4.el8_8.2.x86_64.rpm SHA-256: c947caba7bbe67c556dfb4a07d112a3770bcf6ed609e89d9f16c6fc29d9f7374 gstreamer1-plugins-bad-free-debuginfo-1.16.1-4.el8_8.2.i686.rpm SHA-256: 3afe218de7129adc87b999a4a33e318793d57ed19d3d161dddf16523222ed92b gstreamer1-plugins-bad-free-debuginfo-1.16.1-4.el8_8.2.x86_64.rpm SHA-256: 51161b14ad84a8755322e802fce83661299e235e6992f1d6f91ce60ecb32058e gstreamer1-plugins-bad-free-debugsource-1.16.1-4.el8_8.2.i686.rpm SHA-256: 4dc7c1936533825fb7489183ef6944766ec678b1d01367884c4340f50b7082e6 gstreamer1-plugins-bad-free-debugsource-1.16.1-4.el8_8.2.x86_64.rpm SHA-256: 7d1e0059e5a8289b3d6477e55a6010fb912f3a20aeba4335ee334db52667f0e6 Red Hat Enterprise Linux Server - TUS 8.8 SRPM gstreamer1-plugins-bad-free-1.16.1-4.el8_8.2.src.rpm SHA-256: 09fba467bc7bca7c917499e5dc53a7c8756af35a2ee9062249549bd7164e5bc9 x86_64 gstreamer1-plugins-bad-free-1.16.1-4.el8_8.2.i686.rpm SHA-256: d1336284eb658bb40d9eee33b921b6f219ec47a4414975b43506c82fa636f86d gstreamer1-plugins-bad-free-1.16.1-4.el8_8.2.x86_64.rpm SHA-256: c947caba7bbe67c556dfb4a07d112a3770bcf6ed609e89d9f16c6fc29d9f7374 gstreamer1-plugins-bad-free-debuginfo-1.16.1-4.el8_8.2.i686.rpm SHA-256: 3afe218de7129adc87b999a4a33e318793d57ed19d3d161dddf16523222ed92b gstreamer1-plugins-bad-free-debuginfo-1.16.1-4.el8_8.2.x86_64.rpm SHA-256: 51161b14ad84a8755322e802fce83661299e235e6992f1d6f91ce60ecb32058e gstreamer1-plugins-bad-free-debugsource-1.16.1-4.el8_8.2.i686.rpm SHA-256: 4dc7c1936533825fb7489183ef6944766ec678b1d01367884c4340f50b7082e6 gstreamer1-plugins-bad-free-debugsource-1.16.1-4.el8_8.2.x86_64.rpm SHA-256: 7d1e0059e5a8289b3d6477e55a6010fb912f3a20aeba4335ee334db52667f0e6 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.8 SRPM gstreamer1-plugins-bad-free-1.16.1-4.el8_8.2.src.rpm SHA-256: 09fba467bc7bca7c917499e5dc53a7c8756af35a2ee9062249549bd7164e5bc9 ppc64le gstreamer1-plugins-bad-free-1.16.1-4.el8_8.2.ppc64le.rpm SHA-256: c49a008b29513849dd276e7543917438141cc3b3cbcb50a9e407eec4e3a1f704 gstreamer1-plugins-bad-free-debuginfo-1.16.1-4.el8_8.2.ppc64le.rpm SHA-256: 08bae39b3db66eb16fad20785d34f982cb5ed8466521ced24b4e111a77a804b0 gstreamer1-plugins-bad-free-debugsource-1.16.1-4.el8_8.2.ppc64le.rpm SHA-256: 104ce14e96369b3b00d5838e525a521dc27a7683121d7cb91004e78346c18595 Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.8 SRPM gstreamer1-plugins-bad-free-1.16.1-4.el8_8.2.src.rpm SHA-256: 09fba467bc7bca7c917499e5dc53a7c8756af35a2ee9062249549bd7164e5bc9 x86_64 gstreamer1-plugins-bad-free-1.16.1-4.el8_8.2.i686.rpm SHA-256: d1336284eb658bb40d9eee33b921b6f219ec47a4414975b43506c82fa636f86d gstreamer1-plugins-bad-free-1.16.1-4.el8_8.2.x86_64.rpm SHA-256: c947caba7bbe67c556dfb4a07d112a3770bcf6ed609e89d9f16c6fc29d9f7374 gstreamer1-plugins-bad-free-debuginfo-1.16.1-4.el8_8.2.i686.rpm SHA-256: 3afe218de7129adc87b999a4a33e318793d57ed19d3d161dddf16523222ed92b gstreamer1-plugins-bad-free-debuginfo-1.16.1-4.el8_8.2.x86_64.rpm SHA-256: 51161b14ad84a8755322e802fce83661299e235e6992f1d6f91ce60ecb32058e gstreamer1-plugins-bad-free-debugsource-1.16.1-4.el8_8.2.i686.rpm SHA-256: 4dc7c1936533825fb7489183ef6944766ec678b1d01367884c4340f50b7082e6 gstreamer1-plugins-bad-free-debugsource-1.16.1-4.el8_8.2.x86_64.rpm SHA-256: 7d1e0059e5a8289b3d6477e55a6010fb912f3a20aeba4335ee334db52667f0e6 The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .
This update addresses two high-severity vulnerabilities (CVE-2026-52720, CVSS 8.8, and CVE-2026-52722, CVSS 7.1) in the gstreamer1-plugins-bad-free package for GStreamer, involving a heap buffer overflow via a crafted VNC server rectangle and a signed integer overflow in VMnc decoder cursor payload handling. The affected versions are specifically Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions and Telecommunications Update Service. The fix is provided in package version 1.16.1-4.el8_8.2, and administrators should apply the update via the referenced Red Hat channels.