[ubuntu/jammy-security] gst-plugins-good1.0 1.20.3-0ubuntu1.7 (Accepted)
Marc Deslauriers
marc.deslauriers at canonical.com
Wed Jul 22 12:46:42 UTC 2026
gst-plugins-good1.0 (1.20.3-0ubuntu1.7) jammy-security; urgency=medium
* SECURITY UPDATE: Heap buffer overflow in Matroska demuxer
- debian/patches/CVE-2026-39043.patch: Add missing parenthesis when
calculating bz2 buffer sizes in gst/matroska/matroska-read-common.c.
- CVE-2026-39043
* SECURITY UPDATE: Integer overflow in WAV parser cue handling
- debian/patches/CVE-2026-39044-1.patch: Fix integer overflow when
checking available buffer size for reading cues in
gst/wavparse/gstwavparse.c.
- debian/patches/CVE-2026-39044-2.patch: Use prepend+reverse instead of
append when building the cues list in gst/wavparse/gstwavparse.c.
- CVE-2026-39044
* SECURITY UPDATE: Integer overflow in WavPack decoder
- debian/patches/CVE-2026-53705-1.patch: Avoid integer overflow when
calculating output buffer size in ext/wavpack/gstwavpackdec.c.
- debian/patches/CVE-2026-53705-2.patch: Use correctly-sized variable
types in ext/wavpack/gstwavpackdec.c.
- debian/patches/CVE-2026-53705-3.patch: Avoid integer overflow when
checking input buffer size in ext/wavpack/gstwavpackdec.c.
- debian/patches/CVE-2026-53705-4.patch: Unmap input buffer directly
after decoding in ext/wavpack/gstwavpackdec.c.
- CVE-2026-53705
Date: 2026-07-17 18:59:11.228732+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.20.3-0ubuntu1.7
-------------- next part --------------
Sorry, changesfile not available.
More information about the jammy-changes
mailing list