Skip to content
Red HatCVE-2026-14935

Red Hat GStreamer: incorrect control flow

Low3.7CVE-2026-14935 · Published Jul 7, 2026 · updated Jul 8, 2026

A logic vulnerability was found in GStreamer's webrtcbin component. The _check_sdp_crypto() function contains an inverted boolean condition that causes it to accept remote SDP offers or answers that lack the required a=fingerprint attribute, while incorrectly rejecting those that include it. An attacker with the ability to intercept and modify WebRTC signaling messages could exploit this to bypass the SDP-level DTLS certificate fingerprint binding, weakening defenses against man-in-the-middle attacks on media streams.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat Enterprise Linux 10
Product
all versionsNo fix yet
Red Hat Enterprise Linux 6
Product
all versionsNo fix yet
Red Hat Enterprise Linux 7
Product
all versionsNo fix yet
all versionsNo fix yet
Red Hat Enterprise Linux 8
Product
all versionsNo fix yet
Red Hat Enterprise Linux 9
Product
all versionsNo fix yet
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat Jastow: cross-site scripting
Medium6.5Jul 7
Red Hat 389-ds-base: attacker could detect plaintext equality across encrypted
Medium4.4Jul 7
Red Hat Directory Server 11: denial of service
Medium5.3Jul 7
Red Hat 389-ds-base: buffer overflow
High8.8Jul 7
Red Hat SSSD: insecure default
High8.8Jul 7
Red Hat SSSD: path traversal
High8.0Jul 7

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.