elsa-2026-36834
oracle_linux[1.22.12-7.1] - Sync with c9s release -5..-7: fix for CVE-2026-2923, CVE-2026-3082 in dvbsuboverlay and jpegparser Resolves: RHEL-156242, RHEL-156255 [1.22.12-4.4] - Fix bytes/bits confusion in AV1 tile data size parsing (CVE-2026-52718) Resolves: RHEL-184388 [1.22.12-4.3] - Fix for CVE-2026-52719: vajpegdecoder out-of-bounds read Resolves: RHEL-184403 [1.22.12-4.2] - Fix integer overflows in vmnc decoder (CVE-2026-52722) Resolves: RHEL-184422 [1.22.12-4.1] - Fix for CVE-2026-52720: validate framebuffer update rectangles in librfb plugin Resolves: RHEL-184459 [1.22.12-4] - fix for CVE-2025-3887 Resolves: RHEL-93059 [1.22.12-3] - Rebuild - Resolves: RHEL-38511, RHEL-41157 [1.22.12-2] - Rebuild - Resolves: RHEL-38511, RHEL-41157
- Published
- unknown
- Last Modified
- unknown
CVSS details not available.
No product information available.
No references available.
No linked vulnerabilities found.
{
"cves": [
"CVE-2026-52718",
"CVE-2026-52719",
"CVE-2026-52720",
"CVE-2026-52722"
],
"cvss": 0.0,
"database_specific": {
"severity": "IMPORTANT"
},
"description": "[1.22.12-7.1]\n- Sync with c9s release -5..-7: fix for CVE-2026-2923, CVE-2026-3082\n in dvbsuboverlay and jpegparser\n Resolves: RHEL-156242, RHEL-156255\n\n[1.22.12-4.4]\n- Fix bytes/bits confusion in AV1 tile data size parsing\n (CVE-2026-52718)\n Resolves: RHEL-184388\n\n[1.22.12-4.3]\n- Fix for CVE-2026-52719: vajpegdecoder out-of-bounds read\n Resolves: RHEL-184403\n\n[1.22.12-4.2]\n- Fix integer overflows in vmnc decoder (CVE-2026-52722)\n Resolves: RHEL-184422\n\n[1.22.12-4.1]\n- Fix for CVE-2026-52720: validate framebuffer update rectangles\n in librfb plugin\n Resolves: RHEL-184459\n\n[1.22.12-4]\n- fix for CVE-2025-3887\n Resolves: RHEL-93059\n\n[1.22.12-3]\n- Rebuild\n- Resolves: RHEL-38511, RHEL-41157\n\n[1.22.12-2]\n- Rebuild\n- Resolves: RHEL-38511, RHEL-41157",
"id": "ELSA-2026-36834",
"ovalId": "oval:com.oracle.elsa:def:202636834",
"source": "oracle_linux",
"title": "ELSA-2026-36834: gstreamer1-plugins-bad-free security update (IMPORTANT)",
"url": "https://linux.oracle.com/errata/ELSA-2026-36834.html"
}