Critical Vulnerability in GStreamer Good Plugins Affects Ubuntu 25.10

Critical Vulnerability in GStreamer Good Plugins Affects Ubuntu 25.10

First seen 21 May 2026, 03:26 UTC UbuntuLinuxsecuritylaunchpad.net 87% similarity 70.5

Article Content

Browse articles
ThreatCluster

A vulnerability in GStreamer Good Plugins has been identified, allowing remote attackers to crash the software or execute arbitrary code by exploiting specially crafted MOV/MP4 media files. This issue affects Ubuntu 25.10 and its derivatives. The vulnerability could lead to denial of service, posing significant risks to users. Affected package versions include gstreamer1.0-plugins-good 1.26.5-1ubuntu2.2 and libgstreamer-plugins-good1.0-0 1.26.5-1ubuntu2.2. Users are advised to apply standard system updates to mitigate the risk. The vulnerability has been assigned a CVE identifier, CVE-2026, although specific details on the CVE number were not provided in the articles. The problem was confirmed on May 20, 2026, with advisories published by both Ubuntu and Linuxsecurity.

Key Points: • GStreamer Good Plugins vulnerability allows remote code execution via crafted media files. • Affected systems include Ubuntu 25.10 and its derivatives, requiring urgent updates. • Users should update to specific package versions to mitigate denial of service risks.

ThreatCluster AI

Timeline

2026-05-20
Vulnerability discovered in GStreamer Good Plugins
A flaw was found that allows remote attackers to crash the software or execute arbitrary code through specially crafted MOV/MP4 files.
Ubuntu
2026-05-20
Advisories published by Ubuntu and Linuxsecurity
Both sources reported the vulnerability and recommended updates to affected package versions.
Linuxsecurity

Community

Browse all →