Skip to content
Rota Nacional

Cyber ·

USN-8896-1: code execution and denial of service flaws in GStreamer Ugly Plugins

Ubuntu Security advisory on incorrect handling of malformed RealMedia and ASF files in GStreamer Ugly Plugins, with risks of code execution, denial of service and information exposure.

Advisory USN-8896-1 describes flaws in which GStreamer Ugly Plugins incorrectly handle certain malformed RealMedia and ASF files. According to the text, if a user is induced to open a file crafted for this purpose, an attacker could possibly execute arbitrary code, cause denial of service or expose sensitive information. The identifiers cited are CVE-2023-38103, CVE-2023-38104, CVE-2026-2920, CVE-2026-2922, CVE-2026-53703, CVE-2026-53704 and CVE-2026-19389. According to the advisory, CVE-2023-38103 and CVE-2023-38104 affected only Ubuntu 16.04, 18.04, 20.04 and 22.04 LTS, while CVE-2026-2920 and CVE-2026-2922 also affected Ubuntu 24.04 LTS. The feed entry is dated 7 October 2026. The source is an automatic translation of Ubuntu Security content. To verify, consult the official notice by its identifier USN-8896-1 and check the package versions the vendor lists before applying any update. If there is any discrepancy, the original English version should prevail.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 10,00.

Try free