<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T09:12:07.842580+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-73434</id>
    <title>CVE-2026-73434 — Gstreamer1-plugins-good: gstreamer: out-of-bounds read in avidemux vprp video field descriptor parsing</title>
    <updated>2026-10-02T09:12:07.844373+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> GStreamer gst-plugins-good, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 7 Extended Lifecycle Support, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On, Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On, Red Hat Enterprise Linux 8.8 Telecommunications Update Service and 5 more</p>
<p>A flaw was found in GStreamer gst-plugins-good (avidemux). In gst_avi_demux_riff_parse_vprp(), the number of available gst_riff_vprp_video_field_desc entries is calculated by dividing the remaining buffer size by the attacker-controlled vprp-&gt;fields value, rather than by sizeof(gst_riff_vprp_video_field_desc). This can cause the parser to treat more field descriptors as available than fit in the input buffer, resulting in out-of-bounds reads. Processing a crafted AVI via playbin/decodebin can crash the application (denial of service). Fixed upstream in gst-plugins-good 1.28.6 (GStreamer-SA-2026-0072).</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-73434"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/usn-8863-1</id>
    <title>USN-8863-1 — gst-plugins-good1.0 vulnerabilities</title>
    <updated>2026-10-02T09:12:07.844449+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: gst-plugins-good1.0, Ubuntu:Pro:18.04:LTS: gst-plugins-good1.0, Ubuntu:Pro:20.04:LTS: gst-plugins-good1.0, Ubuntu:22.04:LTS: gst-plugins-good1.0, Ubuntu:24.04:LTS: gst-plugins-good1.0, Ubuntu:26.04:LTS: gst-plugins-good1.0</p>
<p>Yazan Balawneh discovered that GStreamer Good Plugins incorrectly handled
certain FLAC audio streams. An attacker could possibly use this issue to
obtain sensitive information. (CVE-2026-17072)</p>
<p>Seonwook Kim discovered that GStreamer Good Plugins incorrectly parsed
certain AVI files. An attacker could possibly use this issue to cause a
denial of service or obtain sensitive information. (CVE-2026-73433)</p>
<p>Seonwook Kim discovered that GStreamer Good Plugins did not correctly parse
certain AVI files. An attacker could possibly use this issue to cause a
denial of service. (CVE-2026-73434)</p>
<p>Seonwook Kim discovered that GStreamer Good Plugins incorrectly handled
certain closed caption data. An attacker could possibly use this issue to
obtain sensitive information. This issue only affected Ubuntu 20.04 LTS,
Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS.
(CVE-2026-88914)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/usn-8863-1"/>
  </entry>
</feed>
