安全公告详情

NS-SA-2026-0088

2026-09-07 18:00:00

简介

important: gstreamer1-plugins-bad-free/libtiff security update

严重级别

important

主题

An update for gstreamer1-plugins-bad-free/libtiff is now available for NewStart CGSL MAIN 7.02.
NewStart Security has rated this update as having a security impact of important. A Common Vunlnerability Scoring System(CVSS)base score, which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.

详细描述

gstreamer1-plugins-bad-free:
libtiff:


Security Fix(es):
gstreamer1-plugins-bad-free: A stack buffer overflow flaw was found in the GStreamer H.265 codec parser library (gst-plugins-bad). When parsing a buffering period SEI message, the parser uses an incorrect loop bound derived from cpb_cnt_minus1[i] (the loop index) instead of the sub-layer 0 CPB count cpb_cnt_minus1[0] from the referenced Sequence Parameter Set. A crafted H.265 video file or stream can cause the parser to write beyond the bounds of stack-allocated CPB delay arrays, resulting in a crash or potential stack memory corruption.(CVE-2026-53702)
gstreamer1-plugins-bad-free: A stack based buffer overflow was found in the GStreamer media handling library. This flaw allows an attacker who is able to feed in a maliciously constructed H266 file to execute arbitrary code in the context of the process running GStreamer.(CVE-2025-6663)
gstreamer1-plugins-bad-free: A flaw was found in GStreamer. This vulnerability allows a remote attacker to execute arbitrary code by exploiting an out-of-bounds write in the RealMedia Demuxer component. The issue occurs due to improper validation of user-supplied data during the processing of video packets, leading to a write past the end of an allocated buffer. Successful exploitation can result in arbitrary code execution within the context of the current process.(CVE-2026-2922)
gstreamer1-plugins-bad-free: An out-of-bounds write vulnerability was found in GStreamer's H.266/VVC PPS picture partition parser in gst-plugins-bad. In the multi-slice-in-tile processing of gst_h266_parser_parse_picture_partition() (gsth266parser.c), the loop iterates without checking that the slice index stays within bounds, writing past three fixed-size arrays (slice_height_in_ctus, slice_top_left_ctu_x, slice_top_left_ctu_y) in the GstH266PPS structure. While the initial proof-of-concept demonstrated a 4-byte out-of-bounds write, the code permits larger writes across multiple iterations. A crafted H.266/VVC media file can trigger this vulnerability.(CVE-2026-53701)
gstreamer1-plugins-bad-free: A denial of service vulnerability was found in GStreamer's AV1 codec parser in gst-plugins-bad. The gst_av1_parser_parse_tile_list_obu() function passes a byte count to a bit-reader API that expects a bit count, causing parser desynchronization. A remote attacker could trick a user into opening a specially crafted AV1 media file, triggering an assertion abort and causing the application to crash.(CVE-2026-52718)
gstreamer1-plugins-bad-free: An out-of-bounds read vulnerability was found in the VA JPEG decoder in GStreamer's gst-plugins-bad. The JPEG parser reads a segment length value from the bitstream without validating it against available data. A remote attacker could trick a user into opening a specially crafted JPEG file, causing downstream parsing to read beyond the provided input buffer, leading to a crash or potential information disclosure.(CVE-2026-52719)
gstreamer1-plugins-bad-free: bugfix
libtiff: A flaw was found in libtiff. The `PS_Lvl2page` function in `tiff2ps.c` exhibits a null pointer dereference due to improper handling of input data, potentially allowing a local attacker to trigger a denial of service via a crafted file. This manipulation results in the program attempting to access invalid memory locations. This vulnerability stems from a lack of sufficient validation of data structures.(CVE-2025-8534)
libtiff: A null pointer dereference flaw was found in Libtiff via `tif_dirinfo.c`. This issue may allow an attacker to trigger memory allocation failures through certain means, such as restricting the heap space size or injecting faults, causing a segmentation fault. This can cause an application crash, eventually leading to a denial of service.(CVE-2024-7006)
libtiff: A flaw was found in libtiff. The `t2p_read_tiff_init` function in the fax2ps component incorrectly handles TIFF files, leading to a null pointer dereference. A local attacker can trigger this condition by providing a specially crafted TIFF file. This can result in an application level denial of service.(CVE-2024-13978)
libtiff: A flaw was found in the libtiff library. A remote attacker could exploit a signed integer overflow vulnerability in the putcontig8bitYCbCr44tile function by providing a specially crafted TIFF file. This flaw can lead to an out-of-bounds heap write due to incorrect memory pointer calculations, potentially causing a denial of service (application crash) or arbitrary code execution.(CVE-2026-4775)
libtiff: A memory leak flaw was found in LibTIFF. This vulnerability affects the _TIFFmallocExt/_TIFFCheckRealloc/TIFFHashSetNew/InitCCITTFax3 function in the file tools/tiffcmp.c of the tiffcmp component. Executing manipulation can lead to a memory leak. The attack is restricted to local execution.(CVE-2025-9165)
libtiff: bugfix


Solution:
For details on how to apply this update, which includes the changes described in this advisory, refer to:
http://security.gd-linux.com/how_to_apply_patch.html
Remember the build tag is 7.02.07B5.

影响组件

  • gstreamer1-plugins-bad-free
  • libtiff

影响产品

  • CGSL MAIN 7.02

更新包

{"fix":[{"product":"CGSL MAIN 7.02","pkgs":[{"binary":["gstreamer1-plugins-bad-free-1.28.1-3.zncgsl7.x86_64.rpm","gstreamer1-plugins-bad-free-libs-1.28.1-3.zncgsl7.x86_64.rpm","gstreamer1-plugins-bad-free-devel-1.28.1-3.zncgsl7.x86_64.rpm","gstreamer1-plugins-bad-free-doc-1.28.1-3.zncgsl7.noarch.rpm"],"source":"gstreamer1-plugins-bad-free-1.28.1-3.zncgsl7.src.rpm"},{"binary":["libtiff-4.7.1-2.zncgsl7.x86_64.rpm","libtiff-devel-4.7.1-2.zncgsl7.x86_64.rpm","libtiff-tools-4.7.1-2.zncgsl7.x86_64.rpm","libtiff-doc-4.7.1-2.zncgsl7.noarch.rpm"],"source":"libtiff-4.7.1-2.zncgsl7.src.rpm"}]}]}

CVE

参考