Yazan Balawneh discovered that GStreamer Good Plugins incorrectly handled certain FLAC audio streams. An attacker could possibly use this issue to obtain sensitive information. (CVE-2026-17072)
Seonwook Kim discovered that GStreamer Good Plugins incorrectly parsed certain AVI files. An attacker could possibly use this issue to cause a denial of service or obtain sensitive information. (CVE-2026-73433)
Seonwook Kim discovered that GStreamer Good Plugins did not correctly parse certain AVI files. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-73434)
Seonwook Kim discovered that GStreamer Good Plugins incorrectly handled certain closed caption data. An attacker could possibly use this issue to obtain sensitive information. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-88914)
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "gstreamer1.0-gtk3",
"binary_version": "1.20.3-0ubuntu1.10"
},
{
"binary_name": "gstreamer1.0-plugins-good",
"binary_version": "1.20.3-0ubuntu1.10"
},
{
"binary_name": "gstreamer1.0-pulseaudio",
"binary_version": "1.20.3-0ubuntu1.10"
},
{
"binary_name": "gstreamer1.0-qt5",
"binary_version": "1.20.3-0ubuntu1.10"
},
{
"binary_name": "libgstreamer-plugins-good1.0-0",
"binary_version": "1.20.3-0ubuntu1.10"
}
]
}{
"cves": [
{
"id": "CVE-2026-17072",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-73433",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-73434",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-88914",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
}
],
"ecosystem": "Ubuntu:22.04:LTS"
}
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8863-1.json"
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "gstreamer1.0-gtk3",
"binary_version": "1.24.2-1ubuntu1.8"
},
{
"binary_name": "gstreamer1.0-plugins-good",
"binary_version": "1.24.2-1ubuntu1.8"
},
{
"binary_name": "gstreamer1.0-pulseaudio",
"binary_version": "1.24.2-1ubuntu1.8"
},
{
"binary_name": "gstreamer1.0-qt5",
"binary_version": "1.24.2-1ubuntu1.8"
},
{
"binary_name": "gstreamer1.0-qt6",
"binary_version": "1.24.2-1ubuntu1.8"
},
{
"binary_name": "libgstreamer-plugins-good1.0-0",
"binary_version": "1.24.2-1ubuntu1.8"
}
]
}{
"cves": [
{
"id": "CVE-2026-17072",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-73433",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-73434",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-88914",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
}
],
"ecosystem": "Ubuntu:24.04:LTS"
}
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8863-1.json"
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "gstreamer1.0-gtk3",
"binary_version": "1.28.2-2ubuntu0.4"
},
{
"binary_name": "gstreamer1.0-plugins-good",
"binary_version": "1.28.2-2ubuntu0.4"
},
{
"binary_name": "gstreamer1.0-pulseaudio",
"binary_version": "1.28.2-2ubuntu0.4"
},
{
"binary_name": "gstreamer1.0-qt5",
"binary_version": "1.28.2-2ubuntu0.4"
},
{
"binary_name": "gstreamer1.0-qt6",
"binary_version": "1.28.2-2ubuntu0.4"
}
]
}{
"cves": [
{
"id": "CVE-2026-17072",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-73433",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-73434",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-88914",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
}
],
"ecosystem": "Ubuntu:26.04:LTS"
}
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8863-1.json"
{
"availability": "Available with Ubuntu Pro with Legacy support add-on: https://ubuntu.com/pro",
"binaries": [
{
"binary_name": "gstreamer1.0-plugins-good",
"binary_version": "1.8.3-1ubuntu0.5+esm4"
},
{
"binary_name": "gstreamer1.0-pulseaudio",
"binary_version": "1.8.3-1ubuntu0.5+esm4"
},
{
"binary_name": "libgstreamer-plugins-good1.0-0",
"binary_version": "1.8.3-1ubuntu0.5+esm4"
}
]
}{
"cves": [
{
"id": "CVE-2026-17072",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-73433",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-73434",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
}
],
"ecosystem": "Ubuntu:Pro:16.04:LTS"
}
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8863-1.json"
{
"availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
"binaries": [
{
"binary_name": "gstreamer1.0-gtk3",
"binary_version": "1.14.5-0ubuntu1~18.04.3+esm4"
},
{
"binary_name": "gstreamer1.0-plugins-good",
"binary_version": "1.14.5-0ubuntu1~18.04.3+esm4"
},
{
"binary_name": "gstreamer1.0-pulseaudio",
"binary_version": "1.14.5-0ubuntu1~18.04.3+esm4"
},
{
"binary_name": "gstreamer1.0-qt5",
"binary_version": "1.14.5-0ubuntu1~18.04.3+esm4"
},
{
"binary_name": "libgstreamer-plugins-good1.0-0",
"binary_version": "1.14.5-0ubuntu1~18.04.3+esm4"
}
]
}{
"cves": [
{
"id": "CVE-2026-17072",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-73433",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-73434",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
}
],
"ecosystem": "Ubuntu:Pro:18.04:LTS"
}
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8863-1.json"
{
"availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
"binaries": [
{
"binary_name": "gstreamer1.0-gtk3",
"binary_version": "1.16.3-0ubuntu1.3+esm4"
},
{
"binary_name": "gstreamer1.0-plugins-good",
"binary_version": "1.16.3-0ubuntu1.3+esm4"
},
{
"binary_name": "gstreamer1.0-pulseaudio",
"binary_version": "1.16.3-0ubuntu1.3+esm4"
},
{
"binary_name": "gstreamer1.0-qt5",
"binary_version": "1.16.3-0ubuntu1.3+esm4"
},
{
"binary_name": "libgstreamer-plugins-good1.0-0",
"binary_version": "1.16.3-0ubuntu1.3+esm4"
}
]
}{
"cves": [
{
"id": "CVE-2026-17072",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-73433",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-73434",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-88914",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
}
],
"ecosystem": "Ubuntu:Pro:20.04:LTS"
}
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8863-1.json"