USN-8896-1: GStreamer Ugly Plugins flaws, risk of code execution
Ubuntu reports vulnerabilities in GStreamer Ugly Plugins related to malformed RealMedia and ASF files: potential arbitrary code execution.
UptimeMag editorial team · 8 October 2026 · 1 min read

Ubuntu has published security notice USN-8896-1, concerning GStreamer Ugly Plugins. This affects anyone running Ubuntu servers with multimedia components installed, including machines used for server-side audio/video processing or conversion.
What the notice says
According to the official Ubuntu notice (https://ubuntu.com/security/notices/USN-8896-1), researcher Michael Randrianantenaina discovered that GStreamer Ugly Plugins incorrectly handles certain malformed RealMedia files. If a user is tricked into opening a specially crafted media file, an attacker could exploit this issue to execute arbitrary code. This issue, tracked as CVE-2023-38103 and CVE-2023-38104, only affects Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 22.04 LTS.
It was also discovered that GStreamer Ugly Plugins incorrectly handles certain malformed ASF and RealMedia files, with the same potential impact: code execution via opening a malicious file.
What to do
The source text breaks off before listing the updated packages and the corrected version numbers. Anyone running Ubuntu systems with GStreamer Ugly Plugins installed should consult the official notice page for full details on the affected versions and the update command, which is typically:
sudo apt update && sudo apt install --only-upgrade gstreamer1.0-plugins-ugly
(the exact package name and the fixed version should be verified on the notice page before proceeding).
Who is affected
The attack vector requires user interaction: opening a malformed media file. On servers that automatically process uploaded audio/video files (for example, transcoding pipelines), the risk is more concrete, since processing can take place without direct human oversight.
For full details, including the fixed package versions for each LTS release, refer to the official USN-8896-1 notice page at ubuntu.com/security/notices.
Written with the help of artificial intelligence and checked by the editors (EU AI Act, art. 50). Source: Ubuntu – avvisi di sicurezza.