MiracleLinux 8 : gstreamer1-plugins-good-1.16.1-7.el8_10.8 (AXBA:2026-1806:08)

medium Nessus Plugin ID 344584

Synopsis

The remote MiracleLinux host is missing a security update.

Description

The remote MiracleLinux 8 host has packages installed that are affected by a vulnerability as referenced in the AXBA:2026-1806:08 advisory.

- A flaw was found in GStreamer gst-plugins-good (avidemux). When parsing FUJIFILM metadata in an AVI strd chunk, gst_avi_demux_parse_strd() decrements a remaining-length counter by fixed offsets (98 and 10 bytes) without verifying sufficient data remains. For crafted strd payloads of exactly 106 or 107 bytes, the counter underflows to a very large unsigned value, causing subsequent null-terminated string scanning to read far beyond the allocated heap buffer. Date-format normalization may also write beyond the buffer end.
Confirmed impacts include heap out-of-bounds read, out-of-bounds write, heap information disclosure (adjacent data appearing in parsed metadata), and application crash/denial of service. The avidemux element is auto-plugged by playbin, decodebin, and gst-discoverer, so opening or previewing a crafted AVI is sufficient to trigger the issue. Fixed upstream in gst-plugins-good 1.28.6 (GStreamer-SA-2026-0072).
(CVE-2026-73433)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Update the affected gstreamer1-plugins-good and / or gstreamer1-plugins-good-gtk packages.

See Also

https://tsn.miraclelinux.com/en/node/24631

Plugin Details

Severity: Medium

ID: 344584

File Name: miracle_linux_AXBA-2026-1806.nasl

Version: 1.1

Type: Local

Published: 9/10/2026

Updated: 9/10/2026

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.9

Percentile: 52.47

Vendor

Vendor Severity: N/a

CVSS v2

Risk Factor: Medium

Base Score: 6.1

Temporal Score: 4.5

Vector: CVSS2#AV:L/AC:L/Au:N/C:P/I:P/A:C

CVSS Score Source: CVE-2026-73433

CVSS v3

Risk Factor: Medium

Base Score: 6.6

Temporal Score: 5.8

Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:miracle:linux:8, p-cpe:/a:miracle:linux:gstreamer1-plugins-good-gtk, p-cpe:/a:miracle:linux:gstreamer1-plugins-good

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/MiracleLinux/release, Host/MiracleLinux/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 9/10/2026

Vulnerability Publication Date: 8/12/2026

Reference Information

CVE: CVE-2026-73433