Red Hat Product Errata RHSA-2026:49508 - Security Advisory Issued: 2026-08-03 Updated: 2026-08-03 RHSA-2026:49508 - Security Advisory Overview Updated Packages Synopsis Important: gstreamer1-plugins-good security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for gstreamer1-plugins-good is now available for Red Hat Enterprise Linux 10. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description GStreamer is a streaming media framework based on graphs of filters which operate on media data. The gstreamer1-plugins-good packages contain a collection of well-supported plug-ins of good quality and under the LGPL license. Security Fix(es): gstreamer: GStreamer: Arbitrary code execution via stack-based buffer overflow in qtdemux (CVE-2026-5056) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 10 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 x86_64 Red Hat Enterprise Linux for IBM z Systems 10 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 s390x Red Hat Enterprise Linux for Power, little endian 10 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2 ppc64le Red Hat Enterprise Linux for ARM 64 10 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.2 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.2 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.2 s390x Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.2 ppc64le Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.2 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 10.2 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 10.2 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 10.2 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 10.2 s390x Fixes BZ - 2508623 - CVE-2026-5056 gstreamer: GStreamer: Arbitrary code execution via stack-based buffer overflow in qtdemux CVEs CVE-2026-5056 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 10 SRPM gstreamer1-plugins-good-1.26.7-2.el10_2.2.src.rpm SHA-256: 24ffa13112c822cc519100fd4f86f420f31bb5fc8fd43e41e7971aafdf236862 x86_64 gstreamer1-plugins-good-1.26.7-2.el10_2.2.x86_64.rpm SHA-256: 84c8953ccb8c4c0e8d614ee5d96b3d9a26fadae46400910e43716c36101ec5a5 gstreamer1-plugins-good-debuginfo-1.26.7-2.el10_2.2.x86_64.rpm SHA-256: 7e2af648259c278139581215d7a6c4c11fcba6b4eae82d6715b31e931d8ec24b gstreamer1-plugins-good-debugsource-1.26.7-2.el10_2.2.x86_64.rpm SHA-256: e5715be4df213f5b9a06d30f2f1c33d30d8e50e1a062dfaab33d45d281f19658 gstreamer1-plugins-good-gtk-1.26.7-2.el10_2.2.x86_64.rpm SHA-256: 1be6e857769c3fc41b78b1cf3632757105472b88ce32667b3c845bcb3f931c02 gstreamer1-plugins-good-gtk-debuginfo-1.26.7-2.el10_2.2.x86_64.rpm SHA-256: c1843f37a7c5ef6b7d4986c05eb5126e5dff997072fcfeba44061721aaf4dd24 gstreamer1-plugins-good-qt6-debuginfo-1.26.7-2.el10_2.2.x86_64.rpm SHA-256: f049ff8f336652cfdc63f1389d776ee5bd95c2cf52d3bea5a5b7a179fa28936d Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 SRPM gstreamer1-plugins-good-1.26.7-2.el10_2.2.src.rpm SHA-256: 24ffa13112c822cc519100fd4f86f420f31bb5fc8fd43e41e7971aafdf236862 x86_64 gstreamer1-plugins-good-1.26.7-2.el10_2.2.x86_64.rpm SHA-256: 84c8953ccb8c4c0e8d614ee5d96b3d9a26fadae46400910e43716c36101ec5a5 gstreamer1-plugins-good-debuginfo-1.26.7-2.el10_2.2.x86_64.rpm SHA-256: 7e2af648259c278139581215d7a6c4c11fcba6b4eae82d6715b31e931d8ec24b gstreamer1-plugins-good-debugsource-1.26.7-2.el10_2.2.x86_64.rpm SHA-256: e5715be4df213f5b9a06d30f2f1c33d30d8e50e1a062dfaab33d45d281f19658 gstreamer1-plugins-good-gtk-1.26.7-2.el10_2.2.x86_64.rpm SHA-256: 1be6e857769c3fc41b78b1cf3632757105472b88ce32667b3c845bcb3f931c02 gstreamer1-plugins-good-gtk-debuginfo-1.26.7-2.el10_2.2.x86_64.rpm SHA-256: c1843f37a7c5ef6b7d4986c05eb5126e5dff997072fcfeba44061721aaf4dd24 gstreamer1-plugins-good-qt6-debuginfo-1.26.7-2.el10_2.2.x86_64.rpm SHA-256: f049ff8f336652cfdc63f1389d776ee5bd95c2cf52d3bea5a5b7a179fa28936d Red Hat Enterprise Linux for IBM z Systems 10 SRPM gstreamer1-plugins-good-1.26.7-2.el10_2.2.src.rpm SHA-256: 24ffa13112c822cc519100fd4f86f420f31bb5fc8fd43e41e7971aafdf236862 s390x gstreamer1-plugins-good-1.26.7-2.el10_2.2.s390x.rpm SHA-256: da61a3deb9032c5658569a2ff237a5d0b75634d05c43e1f155640c916aa16067 gstreamer1-plugins-good-debuginfo-1.26.7-2.el10_2.2.s390x.rpm SHA-256: 2094092c36459a18fff4154b577724b577d8f5717bc015af695f553f137f01e5 gstreamer1-plugins-good-debugsource-1.26.7-2.el10_2.2.s390x.rpm SHA-256: f7ccf5bb629fcd439cd7c384d534df262792aa9c8d632bee1ebd98787b91184e gstreamer1-plugins-good-gtk-1.26.7-2.el10_2.2.s390x.rpm SHA-256: e361091bb2eacc74f79db9324817b7097409b7d7021f653edcfe56e2c3d25860 gstreamer1-plugins-good-gtk-debuginfo-1.26.7-2.el10_2.2.s390x.rpm SHA-256: ac8c91af657b40efab937d856bec63efc589d9bea697d888150c0666d996928a gstreamer1-plugins-good-qt6-debuginfo-1.26.7-2.el10_2.2.s390x.rpm SHA-256: 20c471ad57e6d93f722eb72fb552397124a250caba5648d4d07a92606173127c Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 SRPM gstreamer1-plugins-good-1.26.7-2.el10_2.2.src.rpm SHA-256: 24ffa13112c822cc519100fd4f86f420f31bb5fc8fd43e41e7971aafdf236862 s390x gstreamer1-plugins-good-1.26.7-2.el10_2.2.s390x.rpm SHA-256: da61a3deb9032c5658569a2ff237a5d0b75634d05c43e1f155640c916aa16067 gstreamer1-plugins-good-debuginfo-1.26.7-2.el10_2.2.s390x.rpm SHA-256: 2094092c36459a18fff4154b577724b577d8f5717bc015af695f553f137f01e5 gstreamer1-plugins-good-debugsource-1.26.7-2.el10_2.2.s390x.rpm SHA-256: f7ccf5bb629fcd439cd7c384d534df262792aa9c8d632bee1ebd98787b91184e gstreamer1-plugins-good-gtk-1.26.7-2.el10_2.2.s390x.rpm SHA-256: e361091bb2eacc74f79db9324817b7097409b7d7021f653edcfe56e2c3d25860 gstreamer1-plugins-good-gtk-debuginfo-1.26.7-2.el10_2.2.s390x.rpm SHA-256: ac8c91af657b40efab937d856bec63efc589d9bea697d888150c0666d996928a gstreamer1-plugins-good-qt6-debuginfo-1.26.7-2.el10_2.2.s390x.rpm SHA-256: 20c471ad57e6d93f722eb72fb552397124a250caba5648d4d07a92606173127c Red Hat Enterprise Linux for Power, little endian 10 SRPM gstreamer1-plugins-good-1.26.7-2.el10_2.2.src.rpm SHA-256: 24ffa13112c822cc519100fd4f86f420f31bb5fc8fd43e41e7971aafdf236862 ppc64le gstreamer1-plugins-good-1.26.7-2.el10_2.2.ppc64le.rpm SHA-256: 6ce1c8fd7e556d8a0b191d23ff908d60ad6008bb4941fa171c038df025fd39a8 gstreamer1-plugins-good-debuginfo-1.26.7-2.el10_2.2.ppc64le.rpm SHA-256: 6ccd5e0a44d2cc50534323104639e29f0b87e640cd19f66e57ac01b4bd1e7b25 gstreamer1-plugins-good-debugsource-1.26.7-2.el10_2.2.ppc64le.rpm SHA-256: 9ab172d34429423f6241515969a606943abf83c1a12963e092f424af339f46bf gstreamer1-plugins-good-gtk-1.26.7-2.el10_2.2.ppc64le.rpm SHA-256: db3c72c46ddd9c46fd77e9ef4bc46c7acaab321adf5493051789763514815039 gstreamer1-plugins-good-gtk-debuginfo-1.26.7-2.el10_2.2.ppc64le.rpm SHA-256: 9377f67d64e2170fa837e0fb71e52d2b6d5ee45861e12ba3bb5039eb90db7e03 gstreamer1-plugins-good-qt6-debuginfo-1.26.7-2.el10_2.2.ppc64le.rpm SHA-256: f33d2cc7a2427dae9bfd1f2edc425b8b15d2e960ca42e540770d977ce99e53c6 Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2 SRPM gstreamer1-plugins-good-1.26.7-2.el10_2.2.src.rpm SHA-256: 24ffa13112c822cc519100fd4f86f420f31bb5fc8fd43e41e7971aafdf236862 ppc64le gstreamer1-plugins-good-1.26.7-2.el10_2.2.ppc64le.rpm SHA-256: 6ce1c8fd7e556d8a0b191d23ff908d60ad6008bb4941fa171c038df025fd39a8 gstreamer1-plugins-good-debuginfo-1.26.7-2.el10_2.2.ppc64le.rpm SHA-256: 6ccd5e0a44d2cc50534323104639e29f0b87e640cd19f66e57ac01b4bd1e7b25 gstreamer1-plugins-good-debugsource-1.26.7-2.el10_2.2.ppc64le.rpm SHA-256: 9ab172d34429423f6241515969a606943abf83c1a12963e092f424af339f46bf gstreamer1-plugins-good-gtk-1.26.7-2.el10_2.2.ppc64le.rpm SHA-256: db3c72c46ddd9c46fd77e9ef4bc46c7acaab321adf5493051789763514815039 gstreamer1-plugins-good-gtk-debuginfo-1.26.7-2.el10_2.2.ppc64le.rpm SHA-256: 9377f67d64e2170fa837e0fb71e52d2b6d5ee45861e12ba3bb5039eb90db7e03 gstreamer1-plugins-good-qt6-debuginfo-1.26.7-2.el10_2.2.ppc64le.rpm SHA-256: f33d2cc7a2427dae9bfd1f2edc425b8b15d2e960ca42e540770d977ce99e53c6 Red Hat Enterprise Linux for ARM 64 10 SRPM gstreamer1-plugins-good-1.26.7-2.el10_2.2.src.rpm SHA-256: 24ffa13112c822cc519100fd4f86f420f31bb5fc8fd43e41e7971aafdf236862 aarch64 gstreamer1-plugins-good-1.26.7-2.el10_2.2.aarch64.rpm SHA-256: 15134ddcb1d70df80f1bff6c83a761474b176c3c0fad80497812678cd4cf4fbc gstreamer1-plugins-good-debuginfo-1.26.7-2.el10_2.2.aarch64.rpm SHA-256: ae75ab244b8fcff63f37a29d67a89bab085721955a61ad39c4869b63e11367e5 gstreamer1-plugins-good-debugsource-1.26.7-2.el10_2.2.aarch64.rpm SHA-256: fa68652e9a75c6133a3103e07df7b71e2630e9f0e624f2d38f9f6bed3f1f335e gstreamer1-plugins-good-gtk-1.26.7-2.el10_2.2.aarch64.rpm SHA-256: 36b46d3b843ee791ecc713e430f5713626fdb18d3a3b92574662a6c2e93e8621 gstreamer1-plugins-good-gtk-debuginfo-1.26.7-2.el10_2.2.aarch64.rpm SHA-256: 7592b7c62bf6c84594a1425e2d2bc1b981095df43d53a2a3089569712b5aa04b gstreamer1-plugins-good-qt6-debuginfo-1.26.7-2.el10_2.2.aarch64.rpm SHA-256: 7b6bb05cbbc64b7af569527cd56e79659364f2abe4ee4125a2bcbbcda976b1cb Red Hat Enterp
A stack-based buffer overflow (CVE-2026-5056, CVSS 7.8) in the qtdemux component of the gstreamer1-plugins-good package allows for arbitrary code execution. The vulnerability affects Red Hat Enterprise Linux 10 systems, and Red Hat has released a security update rated as Important. Administrators should apply the vendor-provided patch via the referenced Red Hat solution article.