<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 09:12:12 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-88914 — Gstreamer1-plugins-good: gstreamer: integer overflow and out-of-bounds read in qtdemux cea-608 closed-caption parser</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-88914</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9&lt;/p&gt;
&lt;p&gt;A flaw was found in GStreamer&amp;#39;s gst-plugins-good isomp4 plugin. When processing a specially crafted MP4 or MOV file containing CEA-608 closed-caption data, an integer overflow in 32-bit unsigned arithmetic can bypass a bounds check in the caption parser. This leads to an out-of-bounds heap read of up to 244 bytes, which is then included in the downstream caption output. An attacker could exploit this by tricking a user into opening a malicious media file, potentially resulting in disclosure of adjacent heap memory or application crash.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9&lt;/p&gt;
&lt;p&gt;A flaw was found in GStreamer&amp;#39;s gst-plugins-good isomp4 plugin. When processing a specially crafted MP4 or MOV file containing CEA-608 closed-caption data, an integer overflow in 32-bit unsigned arithmetic can bypass a bounds check in the caption parser. This leads to an out-of-bounds heap read of up to 244 bytes, which is then included in the downstream caption output. An attacker could exploit this by tricking a user into opening a malicious media file, potentially resulting in disclosure of adjacent heap memory or application crash.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-88914</guid>
    </item>
    <item>
      <title>USN-8863-1 — gst-plugins-good1.0 vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/usn-8863-1</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: gst-plugins-good1.0, Ubuntu:Pro:18.04:LTS: gst-plugins-good1.0, Ubuntu:Pro:20.04:LTS: gst-plugins-good1.0, Ubuntu:22.04:LTS: gst-plugins-good1.0, Ubuntu:24.04:LTS: gst-plugins-good1.0, Ubuntu:26.04:LTS: gst-plugins-good1.0&lt;/p&gt;
&lt;p&gt;Yazan Balawneh discovered that GStreamer Good Plugins incorrectly handled
certain FLAC audio streams. An attacker could possibly use this issue to
obtain sensitive information. (CVE-2026-17072)&lt;/p&gt;
&lt;p&gt;Seonwook Kim discovered that GStreamer Good Plugins incorrectly parsed
certain AVI files. An attacker could possibly use this issue to cause a
denial of service or obtain sensitive information. (CVE-2026-73433)&lt;/p&gt;
&lt;p&gt;Seonwook Kim discovered that GStreamer Good Plugins did not correctly parse
certain AVI files. An attacker could possibly use this issue to cause a
denial of service. (CVE-2026-73434)&lt;/p&gt;
&lt;p&gt;Seonwook Kim discovered that GStreamer Good Plugins incorrectly handled
certain closed caption data. An attacker could possibly use this issue to
obtain sensitive information. This issue only affected Ubuntu 20.04 LTS,
Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS.
(CVE-2026-88914)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: gst-plugins-good1.0, Ubuntu:Pro:18.04:LTS: gst-plugins-good1.0, Ubuntu:Pro:20.04:LTS: gst-plugins-good1.0, Ubuntu:22.04:LTS: gst-plugins-good1.0, Ubuntu:24.04:LTS: gst-plugins-good1.0, Ubuntu:26.04:LTS: gst-plugins-good1.0&lt;/p&gt;
&lt;p&gt;Yazan Balawneh discovered that GStreamer Good Plugins incorrectly handled
certain FLAC audio streams. An attacker could possibly use this issue to
obtain sensitive information. (CVE-2026-17072)&lt;/p&gt;
&lt;p&gt;Seonwook Kim discovered that GStreamer Good Plugins incorrectly parsed
certain AVI files. An attacker could possibly use this issue to cause a
denial of service or obtain sensitive information. (CVE-2026-73433)&lt;/p&gt;
&lt;p&gt;Seonwook Kim discovered that GStreamer Good Plugins did not correctly parse
certain AVI files. An attacker could possibly use this issue to cause a
denial of service. (CVE-2026-73434)&lt;/p&gt;
&lt;p&gt;Seonwook Kim discovered that GStreamer Good Plugins incorrectly handled
certain closed caption data. An attacker could possibly use this issue to
obtain sensitive information. This issue only affected Ubuntu 20.04 LTS,
Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS.
(CVE-2026-88914)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/usn-8863-1</guid>
    </item>
  </channel>
</rss>
