[ubuntu/resolute-security] gst-plugins-good1.0 1.28.2-2ubuntu0.4 (Accepted)

Kyle Kernick kyle.kernick at canonical.com
Thu Oct 1 16:26:39 UTC 2026


gst-plugins-good1.0 (1.28.2-2ubuntu0.4) resolute-security; urgency=medium

  * SECURITY UPDATE: Out-of-bounds read in FLAC parsing
    - debian/patches/CVE-2026-17072.patch: Make sure enough data is
      available when parsing FLAC headers.
      in gst/matroska/matroska-ids.c
    - CVE-2026-17072
  * SECURITY UPDATE: Integer underflow in FUJIFILM metadata parsing
    - debian/patches/CVE-2026-73433.patch: Make sure enough data is available
      when parsing FUJIFILM strd in gst/avi/gstavidemux.c
    - debian/patches/CVE-2026-73433-post1.patch: Improve
      const-correctness in many places in gst/avi/gstavidemux.c
    - CVE-2026-73433
  * SECURITY UPDATE: Out-of-bounds read in gst_avi_demux_riff_parse_vprp
    - debian/patches/CVE-2026-73434.patch: Use correct divisor for
      calculating available number of vprp field infos in
      gst/avi/gstavidemux.c
    - CVE-2026-73434
  * SECURITY UPDATE: Integer overflow in isomp4 plugin
    - debian/patches/CVE-2026-88914-1.patch: Ensure enough data is available
      for reading closed caption boxes in gst/isomp4/qtdemux.c
    - debian/patches/CVE-2026-88914-2.patch: Don't try splitting CEA608
      samples without known framerate in gst/isomp4/qtdemux.c
    - CVE-2026-88914

Date: 2026-09-29 18:34:15.623203+00:00
Changed-By: Kyle Kernick <kyle.kernick at canonical.com>
https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.28.2-2ubuntu0.4
-------------- next part --------------
Sorry, changesfile not available.


More information about the Resolute-changes mailing list