CVE-2026-19389: Red Hat Enterprise Linux 10

High severity, CVSS 7.1. EPSS: 0.6% chance of exploitation in the next 30 days.

Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdemux) when parsing header objects from crafted ASF, WMV, or WMA files. Insufficient validation of attacker-controlled length and size values can bypass bounds checks and cause out-of-bounds heap reads. This can result in application crash, denial of service, or limited information disclosure when untrusted media is processed.

Affected products

  • Red Hat Red Hat Enterprise Linux 10: before 0:1.26.7-2.el10_2.2 (fixed in 0:1.26.7-2.el10_2.2)
  • Red Hat Red Hat Enterprise Linux 10.0 Extended Update Support: before 0:1.24.11-1.el10_0.3 (fixed in 0:1.24.11-1.el10_0.3)
  • Red Hat Red Hat Enterprise Linux 7
  • Red Hat Red Hat Enterprise Linux 8
  • Red Hat Red Hat Enterprise Linux 9: before 0:1.22.12-7.el9_8.4 (fixed in 0:1.22.12-7.el9_8.4); before 0:1.22.12-6.el9_8.2 (fixed in 0:1.22.12-6.el9_8.2)
  • Red Hat Red Hat Enterprise Linux 9.2 Update Services For SAP Solutions: before 0:1.18.4-4.el9_2 (fixed in 0:1.18.4-4.el9_2)
  • Red Hat Red Hat Enterprise Linux 9.4 Update Services For SAP Solutions: before 0:1.22.1-2.el9_4 (fixed in 0:1.22.1-2.el9_4)
  • Red Hat Red Hat Enterprise Linux 9.6 Extended Update Support: before 0:1.22.12-4.el9_6.2 (fixed in 0:1.22.12-4.el9_6.2)

Published 2026-08-10. Last modified 2026-09-16.