{"id":168322,"date":"2026-04-10T17:11:55","date_gmt":"2026-04-10T15:11:55","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/opasnye-uyazvimosti-v-gstreamer-cups-wolfssl-openssl-openclaw-nix-i-yadre-linux"},"modified":"2026-04-10T17:11:55","modified_gmt":"2026-04-10T15:11:55","slug":"opasnye-uyazvimosti-v-gstreamer-cups-wolfssl-openssl-openclaw-nix-i-yadre-linux","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/news\/opasnye-uyazvimosti-v-gstreamer-cups-wolfssl-openssl-openclaw-nix-i-yadre-linux","title":{"rendered":"The release of the Deepin 25.1 distribution, which develops its own graphical environment.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Several dangerous vulnerabilities have been identified in recent days, most of which can be exploited remotely:    <\/p>\n<ul>\n<li class=\"l\"> The corrective release of the multimedia framework GStreamer 1.28.2 has revealed 11 vulnerabilities, three of which are caused by buffer overflows and could potentially lead to code execution when processing specially crafted multimedia container files MKV (CVE not assigned) and MOV\/MP4 (CVE-2026-5056), as well as streams in H.266\/VVC format (CVE not assigned). The remaining eight vulnerabilities are caused by integer overflows or null pointer dereferences, which may lead to denial of service or information leakage when processing data in formats such as WAV, JPEG2000, AV1, H.264, MOV, MP4, FLV, mDVDsub, and SRT\/WebVTT. The danger of vulnerabilities in GStreamer is exacerbated by its use in GNOME for parsing metadata during the automatic indexing of new files, meaning an attacker only needs to get a file loaded into the indexable directory ~\/Downloads.\n<li class=\"l\"> In <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/en\/server\/dts-newyork\/\" title=\"server\" data-wpil-keyword-link=\"linked\">server<\/a> CUPS printing has revealed eight vulnerabilities, two of which (CVE-2026-34980, CVE-2026-34990) can be exploited for remote code execution with root privileges by sending a specially crafted request to the print server. The first vulnerability allows an unauthenticated attacker to execute their code with lp user privileges by sending a specifically crafted print job (the issue arises from improper handling of escaped newline characters). The second vulnerability allows privilege escalation from lp user to root by altering files with root privileges via a dummy printer substitution. An update for CUPS addressing these vulnerabilities is not yet available.\n<li class=\"l\"> A corrective release of the cryptographic library wolfSSL 5.9.1 has been published, addressing 21 vulnerabilities. One issue has been assigned a critical severity level, while 9 others are classified as high (leading to memory corruption). The critical vulnerability (CVE-2026-5194) is caused by a lack of validation for hash size and OID identifier, allowing for the specification of hashes smaller than acceptable to weaken the resilience of ECDSA\/ECC, DSA, ML-DSA, ED25519, and ED448 digital signature generation algorithms, as well as bypassing certificate-based authentication. The vulnerability was discovered by Anthropic engineers during code review with an AI model.\n<li class=\"l\"> Correction releases for the cryptographic library OpenSSL 3.6.2, 3.5.6, 3.4.5, and 3.3.7 have been published, addressing 7 vulnerabilities. The most critical vulnerability (CVE-2026-31790) could lead to the leakage of sensitive data remaining in the buffer after the previous operation. This issue is caused by the use of uninitialized memory when encapsulating RSA KEM RSASVE keys.\n<p>Another vulnerability (CVE-2026-31789) is caused by a buffer overflow and could potentially lead to code execution when converting strings to hexadecimal format while processing specially crafted X.509 certificates. This issue has been rated as non-critical since it only occurs on 32-bit platforms. Other vulnerabilities are caused by reading data from areas outside the buffer, accessing already freed memory, and dereferencing a null pointer.       <\/p>\n<li class=\"l\"> In the OpenClaw AI agent 2026.3.11, which allows AI models to interact within system environments (e.g., running utilities and working with files), a critical vulnerability (CVE-2026-32922) has been fixed with a danger level of 10 out of 10. The vulnerability arises because the '\/pair approve' command did not properly check authorization, enabling any user with pairing privileges to the host (the lowest privilege level, sufficient for access to OpenClaw) to grant administrator rights to themselves and gain full control over the environment. To exploit the vulnerability, it is enough to connect to OpenClaw, request the registration of a fictitious device with operator.admin access, then approve their own request with the '\/pair approve' command and gain full control over the targeted OpenClaw instance and all associated services.\n<p>Just a few days earlier, a similar vulnerability (CVE-2026-33579) was discovered in OpenClaw that allowed bypassing access rights verification and obtaining admin rights. Researchers who identified the issue provided statistics indicating that 135,000 publicly accessible OpenClaw instances were found on the internet, of which 63% allowed connection without authentication.          <\/p>\n<li class=\"l\"> A vulnerability (CVE-2026-39860) has been discovered in the Nix package manager used in the NixOS distribution, rated as critical (9 out of 10). This vulnerability allows for the overwriting of any file in the system, limited by the access rights of the Nix background process, which in NixOS and multi-user installations runs with root privileges. The issue stems from the improper mitigation of vulnerability CVE-2024-27297 in 2024. Exploitation occurs via the replacement of a symbolic link to a directory within an isolated build environment where the build results were written. The vulnerability has been fixed in updates nix 2.34.5, 2.33.4, 2.32.7, 2.31.4, 2.30.4, 2.29.3, and 2.28.6.\n<li class=\"l\"> Five vulnerabilities have been patched in the Linux kernel, identified during experiments with the Claude Code toolchain, affecting subsystems nfsd, io_uring, futex, and ksmbd (1, 2). A vulnerability in the NFS driver allows for the exposure of kernel memory regions through requests sent to the NFS server. The problem originates from an error present since kernel 2.6.0 (2003).                <\/ul>\n<p>Source: <a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=65183\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043d\u044b\u0445 \u0437\u0430 \u043f\u043e\u0441\u043b\u0435\u0434\u043d\u0438\u0435 \u0434\u043d\u0438 \u043e\u043f\u0430\u0441\u043d\u044b\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u0431\u043e\u043b\u044c\u0448\u0438\u043d\u0441\u0442\u0432\u043e \u0438\u0437 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043c\u043e\u0436\u043d\u043e \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e: \u0412 \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u0438\u0440\u0443\u044e\u0449\u0435\u043c \u0440\u0435\u043b\u0438\u0437\u0435 \u043c\u0443\u043b\u044c\u0442\u0438\u043c\u0435\u0434\u0438\u0439\u043d\u043e\u0433\u043e \u0444\u0440\u0435\u0439\u043c\u0432\u043e\u0440\u043a\u0430 GStreamer 1.28.2 \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e 11 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u0438\u0437 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 3 \u0432\u044b\u0437\u0432\u0430\u043d\u044b \u043f\u0435\u0440\u0435\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0435\u043c \u0431\u0443\u0444\u0435\u0440\u0430 \u0438 \u043f\u043e\u0442\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043c\u043e\u0433\u0443\u0442 \u043f\u0440\u0438\u0432\u0435\u0441\u0442\u0438 \u043a \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044e \u043a\u043e\u0434\u0430 \u043f\u0440\u0438 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0435 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043e\u0444\u043e\u0440\u043c\u043b\u0435\u043d\u043d\u044b\u0445 \u043c\u0443\u043b\u044c\u0442\u0438\u043c\u0435\u0434\u0438\u0439\u043d\u044b\u0445 \u043a\u043e\u043d\u0442\u0435\u0439\u043d\u0435\u0440\u043e\u0432 MKV (CVE \u043d\u0435 \u043d\u0430\u0437\u043d\u0430\u0447\u0435\u043d) \u0438 MOV\/MP4 (CVE-2026-5056), \u0430 \u0442\u0430\u043a\u0436\u0435 \u043f\u043e\u0442\u043e\u043a\u043e\u0432 \u0432 \u0444\u043e\u0440\u043c\u0430\u0442\u0435 H.266\/VVC [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":8,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-168322","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043d\u044b\u0445 \u0437\u0430 \u043f\u043e\u0441\u043b\u0435\u0434\u043d\u0438\u0435 \u0434\u043d\u0438 \u043e\u043f\u0430\u0441\u043d\u044b\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u0431\u043e\u043b\u044c\u0448\u0438\u043d\u0441\u0442\u0432\u043e \u0438\u0437 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043c\u043e\u0436\u043d\u043e \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e: \u0412 \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u0438\u0440\u0443\u044e\u0449\u0435\u043c \u0440\u0435\u043b\u0438\u0437\u0435 \u043c\u0443\u043b\u044c\u0442\u0438\u043c\u0435\u0434\u0438\u0439\u043d\u043e\u0433\u043e \u0444\u0440\u0435\u0439\u043c\u0432\u043e\u0440\u043a\u0430 GStreamer 1.28.2 \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e 11.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Erik Peterson\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/news\/opasnye-uyazvimosti-v-gstreamer-cups-wolfssl-openssl-openclaw-nix-i-yadre-linux\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041e\u043f\u0430\u0441\u043d\u044b\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 GStreamer, CUPS, wolfSSL, OpenSSL, OpenClaw, Nix \u0438 \u044f\u0434\u0440\u0435 Linux | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043d\u044b\u0445 \u0437\u0430 \u043f\u043e\u0441\u043b\u0435\u0434\u043d\u0438\u0435 \u0434\u043d\u0438 \u043e\u043f\u0430\u0441\u043d\u044b\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u0431\u043e\u043b\u044c\u0448\u0438\u043d\u0441\u0442\u0432\u043e \u0438\u0437 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043c\u043e\u0436\u043d\u043e \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e: \u0412 \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u0438\u0440\u0443\u044e\u0449\u0435\u043c \u0440\u0435\u043b\u0438\u0437\u0435 \u043c\u0443\u043b\u044c\u0442\u0438\u043c\u0435\u0434\u0438\u0439\u043d\u043e\u0433\u043e \u0444\u0440\u0435\u0439\u043c\u0432\u043e\u0440\u043a\u0430 GStreamer 1.28.2 \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e 11.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/news\/opasnye-uyazvimosti-v-gstreamer-cups-wolfssl-openssl-openclaw-nix-i-yadre-linux\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-04-10T15:11:55+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-04-10T15:11:55+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Dangerous vulnerabilities in GStreamer, CUPS, wolfSSL, OpenSSL, OpenClaw, Nix, and the Linux kernel | ProHoster","description":"Several dangerous vulnerabilities have been identified in recent days, most of which can be exploited remotely: 11 have been found in the corrective release of the multimedia framework GStreamer 1.28.2.","canonical_url":"https:\/\/prohoster.info\/en\/blog\/news\/opasnye-uyazvimosti-v-gstreamer-cups-wolfssl-openssl-openclaw-nix-i-yadre-linux","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041e\u043f\u0430\u0441\u043d\u044b\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 GStreamer, CUPS, wolfSSL, OpenSSL, OpenClaw, Nix \u0438 \u044f\u0434\u0440\u0435 Linux | ProHoster","og:description":"\u041d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043d\u044b\u0445 \u0437\u0430 \u043f\u043e\u0441\u043b\u0435\u0434\u043d\u0438\u0435 \u0434\u043d\u0438 \u043e\u043f\u0430\u0441\u043d\u044b\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u0431\u043e\u043b\u044c\u0448\u0438\u043d\u0441\u0442\u0432\u043e \u0438\u0437 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043c\u043e\u0436\u043d\u043e \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e: \u0412 \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u0438\u0440\u0443\u044e\u0449\u0435\u043c \u0440\u0435\u043b\u0438\u0437\u0435 \u043c\u0443\u043b\u044c\u0442\u0438\u043c\u0435\u0434\u0438\u0439\u043d\u043e\u0433\u043e \u0444\u0440\u0435\u0439\u043c\u0432\u043e\u0440\u043a\u0430 GStreamer 1.28.2 \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e 11.","og:url":"https:\/\/prohoster.info\/en\/blog\/news\/opasnye-uyazvimosti-v-gstreamer-cups-wolfssl-openssl-openclaw-nix-i-yadre-linux","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2026-04-10T15:11:55+00:00","article:modified_time":"2026-04-10T15:11:55+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":[],"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/168322","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=168322"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/168322\/revisions"}],"predecessor-version":[{"id":169178,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/168322\/revisions\/169178"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=168322"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=168322"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=168322"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}