USN-8863-1: four CVEs in GStreamer Good Plugins, patched across all Ubuntu LTS releases
Ubuntu fixes four vulnerabilities in GStreamer Good Plugins (CVE-2026-17072, 73433, 73434, 88914) from 16.04 to 26.04 LTS.
UptimeMag editorial team · 1 October 2026 · 2 min read

Canonical published advisory USN-8863-1 on 1 October 2026, fixing four vulnerabilities in the GStreamer Good Plugins packages across all currently supported Ubuntu LTS releases, from 16.04 to 26.04. For anyone running Ubuntu servers with audio/video transcoding, media pipelines, or simply with the package installed as a desktop dependency, this is an update worth scheduling into the next patch cycle.
The vulnerabilities
According to the official Ubuntu advisory:
- CVE-2026-17072: Yazan Balawneh discovered that GStreamer Good Plugins mishandled certain FLAC audio streams. An attacker could potentially exploit this to obtain sensitive information.
- CVE-2026-73433: Seonwook Kim discovered incorrect parsing of certain AVI files, which could lead to a denial of service or the exposure of sensitive information.
- CVE-2026-73434: Seonwook Kim also found a second flaw in AVI file parsing, with a risk of denial of service.
- CVE-2026-88914: incorrect handling of subtitle (closed caption) data, with possible exposure of sensitive information. This issue only affects Ubuntu 20.04, 22.04, 24.04 and 26.04 LTS.
Affected packages and fixed versions
| Release | Main package | Fixed version |
|---|---|---|
| 26.04 LTS | gstreamer1.0-plugins-good | 1.28.2-2ubuntu0.4 |
| 24.04 LTS | gstreamer1.0-plugins-good | 1.24.2-1ubuntu1.8 |
| 22.04 LTS | gstreamer1.0-plugins-good | 1.20.3-0ubuntu1.10 |
| 20.04 LTS | gstreamer1.0-plugins-good | 1.16.3-0ubuntu1.3+esm4 (requires Ubuntu Pro) |
| 18.04 LTS | gstreamer1.0-plugins-good | 1.14.5-0ubuntu1~18.04.3+esm4 (requires Ubuntu Pro) |
| 16.04 LTS | gstreamer1.0-plugins-good | 1.8.3-1ubuntu0.5+esm4 (requires Ubuntu Pro with the Legacy Support add-on) |
For 20.04, 18.04 and 16.04 LTS, now past standard support, the patch is only available through Ubuntu Pro. For the other releases, a standard system update is all that's needed.
How to apply the fix
On Ubuntu 26.04, 24.04 and 22.04 LTS, a standard system update is sufficient:
apt update && apt upgrade
Anyone still running 20.04, 18.04 or 16.04 LTS needs to check they have an active Ubuntu Pro subscription (free for up to 5 machines) in order to receive the patch. Full details and CVE references are available on the official USN-8863-1 advisory page at ubuntu.com/security/notices.
Written with the help of artificial intelligence and checked by the editors (EU AI Act, art. 50). Source: Ubuntu – avvisi di sicurezza.