Skip to content
Fedora 42 mingw-gstreamer1 Critical Arbitrary Code Exec 2026

Fedora 42 mingw-gstreamer1 Critical Arbitrary Code Exec 2026

Linuxsecurity •LinuxSecurity Advisories • April 5, 2026

GStreamer is a streaming-media framework, based on graphs of filters which operate on media data. Applications using this library can do anything from real-time sound processing to playing videos, and just anything else media-related. Its plug-in-based architecture means that new data types or processing capabilities can be added by installing new plug-ins. Update Information : Update to gstreamer-1.26.11.

GStreamer is a streaming-media framework, based on graphs of filters

which operate on media data. Applications using this library can do

anything from real-time sound processing to playing videos, and just

anything else media-related. Its plug-in-based architecture

means that new data types or processing capabilities can be added by

installing new plug-ins.

Update to gstreamer-1.26.11.

* Fri Mar 27 2026 Sandro Mani - 1.26.11-1 - Update to 1.26.11 * Tue Aug 12 2025 Sandro Mani - 1.26.5-1 - Update to 1.26.5 * Thu Jul 24 2025 Fedora Release Engineering - 1.26.3-2 - Rebuilt for

* Fri Mar 27 2026 Sandro Mani - 1.26.11-1 - Update to 1.26.11 * Tue Aug 12 2025 Sandro Mani - 1.26.5-1 - Update to 1.26.5 * Thu Jul 24 2025 Fedora Release Engineering - 1.26.3-2 - Rebuilt for

[ 1 ] Bug #2447936 - CVE-2026-2920 mingw-gstreamer1: GStreamer: Arbitrary code execution via ASF file processing [fedora-all] [ 2 ] Bug #2448013 - CVE-2026-3084 mingw-gstreamer1: GStreamer: Remote Code Execution via integer underflow in H.266 Codec Parser [fedora-all] [ 3 ] Bug #2448019 - CVE-2026-2922 mingw-gstreamer1: GStreamer: Remote Code Execution via out-of-bounds write in RealMedia Demuxer [fedora-all] [ 4 ] Bug #2448020 - CVE-2026-2921 mingw-gstreamer1: GStreamer: Arbitrary code execution via RIFF palette integer overflow in AVI file handling [fedora-all] [ 5 ] Bug #2448021 - CVE-2026-2923 mingw-gstreamer1: GStreamer: Remote Code Execution via out-of-bounds write in DVB Subtitles handling [fedora-all] Read the Full Advisory

[ 1 ] Bug #2447936 - CVE-2026-2920 mingw-gstreamer1: GStreamer: Arbitrary code execution via ASF file processing [fedora-all] [ 2 ] Bug #2448013 - CVE-2026-3084 mingw-gstreamer1: GStreamer: Remote Code Execution via integer underflow in H.266 Codec Parser [fedora-all] [ 3 ] Bug #2448019 - CVE-2026-2922 mingw-gstreamer1: GStreamer: Remote Code Execution via out-of-bounds write in RealMedia Demuxer [fedora-all] [ 4 ] Bug #2448020 - CVE-2026-2921 mingw-gstreamer1: GStreamer: Arbitrary code execution via RIFF palette integer overflow in AVI file handling [fedora-all] [ 5 ] Bug #2448021 - CVE-2026-2923 mingw-gstreamer1: GStreamer: Remote Code Execution via out-of-bounds write in DVB Subtitles handling [fedora-all]

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-3cc99e7d09' at the command line. For more information, refer to the dnf documentation available at

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-3cc99e7d09' at the command line. For more information, refer to the dnf documentation available at

Extracted Entities