USN-8855-1: GStreamer Bad Plugins vulnerability

Publication date

30 September 2026

Overview

GStreamer Bad Plugins could be made to crash or run programs as your login if it opened a specially crafted file.


Packages

Details

It was discovered that GStreamer Bad Plugins incorrectly validated the size
of multi-channel audio blocks. An attacker could possibly use this issue
with a specially crafted WAV file to cause the program to crash, resulting
in a denial of service, or possibly execute arbitrary code.

It was discovered that GStreamer Bad Plugins incorrectly validated the size
of multi-channel audio blocks. An attacker could possibly use this issue
with a specially crafted WAV file to cause the program to crash, resulting
in a denial of service, or possibly execute arbitrary code.

Update instructions

In general, a standard system update will make all the necessary changes.

Learn more about how to get the fixes.

The problem can be corrected by updating your system to the following package versions:

Ubuntu Release Package Version
26.04 LTS resolute gstreamer1.0-plugins-bad –  1.28.2-1ubuntu1.2
24.04 LTS noble gstreamer1.0-plugins-bad –  1.24.2-1ubuntu4+esm2  
22.04 LTS jammy gstreamer1.0-plugins-bad –  1.20.3-0ubuntu1.1+esm3  
20.04 LTS focal gstreamer1.0-plugins-bad –  1.16.3-0ubuntu1.1+esm2  
18.04 LTS bionic gstreamer1.0-plugins-bad –  1.14.5-0ubuntu1~18.04.1+esm2  
16.04 LTS xenial gstreamer1.0-plugins-bad –  1.8.3-1ubuntu0.2+esm2
14.04 LTS trusty gstreamer1.0-plugins-bad –  1.2.4-1~ubuntu1.1+esm1  

Reduce your security exposure

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.


Have additional questions?

Talk to a member of the team ›