Skip to content
Critical Remote Code Execution Vulnerabilities in GStreamer Plugins

Critical Remote Code Execution Vulnerabilities in GStreamer Plugins

First seen 22 Sep 2026, 13:23 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 23, 2026 at 12:29 UTC
  • Multiple CVEs allow remote code execution via GStreamer plugins.
  • Affected systems include various versions of Ubuntu and Mageia.
  • Immediate updates are recommended to mitigate exploitation risks.

Multiple remote code execution vulnerabilities have been discovered in GStreamer Good Plugins and Mageia's GStreamer OGG file parsing. The vulnerabilities, identified as CVE-2026-18295, CVE-2026-18296, CVE-2026-18298, CVE-2026-18299, and CVE-2026-18297, allow attackers to execute arbitrary code through specially crafted files. Affected systems include various Ubuntu and Mageia versions, with the potential for attackers to gain admin control. The vulnerabilities were published on August 20, 2026, and have been confirmed by multiple sources. Users are advised to update their systems immediately to mitigate the risks associated with these vulnerabilities. The Mageia vulnerability specifically involves a stack-based buffer overflow in OGG file parsing. Both advisories emphasize the urgency of applying patches to prevent exploitation.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2026-08-20
CVE-2026-18295 published
Vulnerability in GStreamer Good Plugins allows remote code execution through MRF files.
Linuxsecurity
2026-08-20
CVE-2026-18296 published
Another vulnerability in GStreamer Good Plugins enables arbitrary code execution via PNG files.
Linuxsecurity
2026-08-20
CVE-2026-18298 published
GStreamer Good Plugins vulnerability allows remote code execution through malformed RTP packets.
Linuxsecurity
2026-08-20
CVE-2026-18299 published
Mageia's GStreamer OGG file parsing vulnerability leads to remote code execution via buffer overflow.
Linuxsecurity
2026-08-20
CVE-2026-18297 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-19
Mageia advisory published
Mageia released an advisory regarding the GStreamer OGG vulnerability, urging users to update.
Linuxsecurity
2026-09-22
Ubuntu advisory published
Ubuntu released an advisory addressing multiple vulnerabilities in GStreamer Good Plugins.
Linuxsecurity

More articles in this cluster (2)

Following this threat?

Track Ubuntu and CVE-2026-18295 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed