Linuxsecurity Critical NULL Pointer Vulnerability in GStreamer Affects Fedora Users
Article Content
- •CVE-2026-85150 is a critical NULL pointer vulnerability in GStreamer.
- •Active exploitation of the vulnerability has been confirmed by CISA.
- •Users must update to GStreamer version 1.28.7 to mitigate risks.
A critical NULL pointer dereference vulnerability (CVE-2026-85150) has been identified in the GStreamer framework, affecting Fedora versions 44 and 45. This flaw allows attackers to exploit the gst_rtsp_message_parse_auth_credentials function, potentially leading to application crashes or arbitrary code execution. The vulnerability was published on September 3, 2026, and has been confirmed to be actively exploited in the wild, prompting advisories from CISA. Users are advised to update to GStreamer version 1.28.7 to mitigate the risk. The vulnerability impacts systems using mingw-gstreamer1-plugins-base and mingw-gstreamer1-plugins-good. The updates were released on September 18, 2026, and administrators are urged to apply them immediately. Failure to update could leave systems vulnerable to exploitation.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (8)
Following this threat?
Track Fedora and CVE-2026-85150 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Oracle Linux Vulnerabilities Allow Admin Control via Chained Flaws Oracle Linux has released important fixes for two vulnerabilities, CVE-2026-55193 and CVE-2026-85150, affecting FreeRDP and GStreamer respectively. CVE-2026-55193, published on 2026-08-19, allows attackers to gain admin control through chained flaws related to RPC gateway checks. CVE-2026-85150, published on…
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…