News

USN-8863-1: four CVEs in GStreamer Good Plugins, patched across all Ubuntu LTS releases

Ubuntu fixes four vulnerabilities in GStreamer Good Plugins (CVE-2026-17072, 73433, 73434, 88914) from 16.04 to 26.04 LTS.

UptimeMag editorial team · 1 October 2026 · 2 min read

USN-8863-1: quattro CVE in GStreamer Good Plugins, patch per tutte le Ubuntu LTS

Canonical published advisory USN-8863-1 on 1 October 2026, fixing four vulnerabilities in the GStreamer Good Plugins packages across all currently supported Ubuntu LTS releases, from 16.04 to 26.04. For anyone running Ubuntu servers with audio/video transcoding, media pipelines, or simply with the package installed as a desktop dependency, this is an update worth scheduling into the next patch cycle.

The vulnerabilities

According to the official Ubuntu advisory:

  • CVE-2026-17072: Yazan Balawneh discovered that GStreamer Good Plugins mishandled certain FLAC audio streams. An attacker could potentially exploit this to obtain sensitive information.
  • CVE-2026-73433: Seonwook Kim discovered incorrect parsing of certain AVI files, which could lead to a denial of service or the exposure of sensitive information.
  • CVE-2026-73434: Seonwook Kim also found a second flaw in AVI file parsing, with a risk of denial of service.
  • CVE-2026-88914: incorrect handling of subtitle (closed caption) data, with possible exposure of sensitive information. This issue only affects Ubuntu 20.04, 22.04, 24.04 and 26.04 LTS.

Affected packages and fixed versions

Release Main package Fixed version
26.04 LTS gstreamer1.0-plugins-good 1.28.2-2ubuntu0.4
24.04 LTS gstreamer1.0-plugins-good 1.24.2-1ubuntu1.8
22.04 LTS gstreamer1.0-plugins-good 1.20.3-0ubuntu1.10
20.04 LTS gstreamer1.0-plugins-good 1.16.3-0ubuntu1.3+esm4 (requires Ubuntu Pro)
18.04 LTS gstreamer1.0-plugins-good 1.14.5-0ubuntu1~18.04.3+esm4 (requires Ubuntu Pro)
16.04 LTS gstreamer1.0-plugins-good 1.8.3-1ubuntu0.5+esm4 (requires Ubuntu Pro with the Legacy Support add-on)

For 20.04, 18.04 and 16.04 LTS, now past standard support, the patch is only available through Ubuntu Pro. For the other releases, a standard system update is all that's needed.

How to apply the fix

On Ubuntu 26.04, 24.04 and 22.04 LTS, a standard system update is sufficient:

apt update && apt upgrade

Anyone still running 20.04, 18.04 or 16.04 LTS needs to check they have an active Ubuntu Pro subscription (free for up to 5 machines) in order to receive the patch. Full details and CVE references are available on the official USN-8863-1 advisory page at ubuntu.com/security/notices.

Written with the help of artificial intelligence and checked by the editors (EU AI Act, art. 50). Source: Ubuntu – avvisi di sicurezza.