Ubuntu Patches Seven GStreamer Ugly Plugins Flaws Triggered by Malicious Media Files
Canonical published security notice USN-8896-1 on 7 October 2026, covering seven vulnerabilities in the GStreamer Ugly Plugins package (gst-plugins-ugly1.0), the media decoding component that Ubuntu desktops and many media-handling servers rely on to play RealMedia and ASF content. Four of the issues — CVE-2023-38103, CVE-2023-38104, CVE-2026-2920 and CVE-2026-2922 — are described as potentially allowing arbitrary code execution when a user is tricked into opening a crafted media file. The two 2023 identifiers affect Ubuntu 16.04 LTS, 18.04 LTS, 20.04 LTS and 22.04 LTS, while CVE-2026-2920 and CVE-2026-2922 additionally reach Ubuntu 24.04 LTS. The remaining three — CVE-2026-53703, CVE-2026-53704 and CVE-2026-19389 — can lead to a denial of service or exposure of sensitive information. Fixed packages are available across 26.04 LTS, 24.04 LTS, 22.04 LTS, 20.04 LTS, 18.04 LTS and 16.04 LTS, with most of them delivered only through Ubuntu Pro ESM Apps rather than the standard update channels.
Canonical has not published a detailed technical breakdown of how each flaw is reached, so the exploitation mechanism should be read only as far as the advisory describes it. What the notice does state consistently is the trigger condition: the plugins incorrectly handle certain malformed RealMedia files in the case of CVE-2023-38103, CVE-2023-38104, CVE-2026-53703 and CVE-2026-53704, certain malformed ASF files in the case of CVE-2026-19389, and both container formats in the case of CVE-2026-2920 and CVE-2026-2922. In every instance the attacker-controlled input is the media file itself, and the victim must be persuaded to open it — there is no indication of a network-facing or unauthenticated path. That places the exposure squarely in the parsing layer, where a file that looks like ordinary video or audio content is enough to drive the decoder into unsafe behaviour. The practical delivery routes are the familiar ones for file-borne flaws: email attachments, shared drives, downloads, and automated media processing pipelines that decode untrusted uploads without a human present.
The strategic concern is reach rather than sophistication. GStreamer is installed by default on Ubuntu desktop images and is pulled in as a dependency by common applications including media players, thumbnailers and file indexers, so a single malformed file opened on a workstation touches a code path that exists on a very large estate. Server-side exposure matters too wherever transcoding or preview generation runs against user-supplied uploads, because in that scenario the "user interaction" requirement is satisfied automatically by the pipeline itself. A further operational wrinkle is the distribution of the fixes: for 26.04, 24.04, 22.04, 20.04 and 18.04 the packages are listed as available through Ubuntu Pro ESM Apps, with Canonical noting that a community fix might become publicly available in the future, meaning estates without Pro entitlement remain on vulnerable builds for now. On current exploitation status, none of the seven CVEs shows evidence of active abuse. FIRST EPSS places CVE-2023-38103 at a 1.5% probability of exploitation in the next 30 days and CVE-2023-38104 at 1.4%, with the 2026 identifiers lower still: CVE-2026-19389 at 0.6%, CVE-2026-53703 and CVE-2026-53704 at 0.5% each, CVE-2026-2920 at 0.4% and CVE-2026-2922 at 0.3%. That profile is consistent with a scheduled maintenance item rather than an incident, though the long tail of unpatched 16.04 and 18.04 systems still running media workloads keeps the residual risk from reaching zero.
Attack Surface
Endpoint, Endpoint OS
Tactics
Execution, Impact
Techniques
- T1203 – Exploitation for Client Execution
- T1204.002 – User Execution: Malicious File
- T1499 – Endpoint Denial of Service
SuperPRO's Threat Countermeasures Procedures
- Update gstreamer1.0-plugins-ugly to the fixed build for your release per USN-8896-1: 1.28.2-1ubuntu0.1~esm1 on 26.04 LTS (resolute), 1.24.1-1ubuntu0.1~esm1 on 24.04 LTS (noble), 1.20.1-1ubuntu0.1~esm1 on 22.04 LTS (jammy), 1.16.2-2ubuntu0.1~esm1 on 20.04 LTS (focal), 1.14.5-0ubuntu1~18.04.1+esm1 on 18.04 LTS (bionic) and 1.8.3-1ubuntu0.1+esm2 on 16.04 LTS (xenial).
- Enable Ubuntu Pro ESM Apps on affected hosts using 'sudo pro attach' followed by 'sudo pro enable esm-apps', because Canonical lists these GStreamer fixes as available through ESM Apps rather than the standard archive for 26.04, 24.04, 22.04, 20.04 and 18.04.
- Inventory exposure with 'dpkg -l gstreamer1.0-plugins-ugly' across the Linux estate and record which hosts still report a version below the USN-8896-1 fixed build, prioritising 16.04 and 18.04 systems where the 2023 code-execution issues CVE-2023-38103 and CVE-2023-38104 apply.
- Remove the package where media decoding is not required, for example on build agents, database and application servers, using 'sudo apt-get remove gstreamer1.0-plugins-ugly', which eliminates the vulnerable RealMedia and ASF demuxers entirely rather than leaving them installed but unused.
- Block or quarantine RealMedia and ASF container files at the mail gateway and web proxy by file extension and content type, specifically .rm, .rmvb, .ra, .ram, .asf, .wmv and .wma, since every issue in this advisory is triggered by opening a crafted file in one of those two formats.
- Where server-side transcoding or thumbnail generation processes user-uploaded media, restrict the GStreamer pipeline to an explicit allow-list of required demuxers and run the decode step under a confined AppArmor profile or an unprivileged container so an out-of-bounds condition in the ASF or RealMedia parser cannot reach the host filesystem.
- Create a detection rule for repeated segfaults or Apport crash reports naming gst-launch-1.0, totem, rhythmbox, tracker-extract or gst-plugin-scanner in /var/log/apport.log and /var/crash, and treat clusters of such crashes following a media file download as a trigger for host investigation.