Amazon Linux 2023 Security Advisory: ALAS2023-2026-3106
Advisory Released Date: 2026-09-29
Advisory Updated Date: 2026-09-29
A NULL pointer dereference flaw was found in GStreamer's RTSP support library. The vulnerability occurs while parsing an Authorization or WWW-Authenticate header that uses Digest authentication. Specially crafted whitespace placement around a parameter's terminator can cause an internal length calculation to underflow, leading to a crash of the process parsing the header. On an RTSP server this can be triggered by a remote, unauthenticated attacker sending a single malformed request when the server has authentication enabled; the same flaw can also be triggered against an RTSP client by a malicious or compromised RTSP server. Successful exploitation results in a denial of service (application crash) and has no confirmed impact on confidentiality or integrity. (CVE-2026-85150)
Affected Packages:
gstreamer1-plugins-base
Issue Correction:
Run dnf update gstreamer1-plugins-base --releasever 2023.12.20260928 or dnf update --advisory ALAS2023-2026-3106 --releasever 2023.12.20260928 to update your system.
More information on how to update your system can be found on this page: Amazon Linux 2023 documentation
aarch64:
gstreamer1-plugins-base-tools-debuginfo-1.24.10-1.amzn2023.0.5.aarch64
gstreamer1-plugins-base-tools-1.24.10-1.amzn2023.0.5.aarch64
gstreamer1-plugins-base-debuginfo-1.24.10-1.amzn2023.0.5.aarch64
gstreamer1-plugins-base-debugsource-1.24.10-1.amzn2023.0.5.aarch64
gstreamer1-plugins-base-devel-1.24.10-1.amzn2023.0.5.aarch64
gstreamer1-plugins-base-1.24.10-1.amzn2023.0.5.aarch64
src:
gstreamer1-plugins-base-1.24.10-1.amzn2023.0.5.src
x86_64:
gstreamer1-plugins-base-tools-debuginfo-1.24.10-1.amzn2023.0.5.x86_64
gstreamer1-plugins-base-debuginfo-1.24.10-1.amzn2023.0.5.x86_64
gstreamer1-plugins-base-tools-1.24.10-1.amzn2023.0.5.x86_64
gstreamer1-plugins-base-devel-1.24.10-1.amzn2023.0.5.x86_64
gstreamer1-plugins-base-debugsource-1.24.10-1.amzn2023.0.5.x86_64
gstreamer1-plugins-base-1.24.10-1.amzn2023.0.5.x86_64