[ubuntu/resolute-security] gst-plugins-good1.0 1.28.2-2ubuntu0.4 (Accepted)
Kyle Kernick
kyle.kernick at canonical.com
Thu Oct 1 16:26:39 UTC 2026
gst-plugins-good1.0 (1.28.2-2ubuntu0.4) resolute-security; urgency=medium
* SECURITY UPDATE: Out-of-bounds read in FLAC parsing
- debian/patches/CVE-2026-17072.patch: Make sure enough data is
available when parsing FLAC headers.
in gst/matroska/matroska-ids.c
- CVE-2026-17072
* SECURITY UPDATE: Integer underflow in FUJIFILM metadata parsing
- debian/patches/CVE-2026-73433.patch: Make sure enough data is available
when parsing FUJIFILM strd in gst/avi/gstavidemux.c
- debian/patches/CVE-2026-73433-post1.patch: Improve
const-correctness in many places in gst/avi/gstavidemux.c
- CVE-2026-73433
* SECURITY UPDATE: Out-of-bounds read in gst_avi_demux_riff_parse_vprp
- debian/patches/CVE-2026-73434.patch: Use correct divisor for
calculating available number of vprp field infos in
gst/avi/gstavidemux.c
- CVE-2026-73434
* SECURITY UPDATE: Integer overflow in isomp4 plugin
- debian/patches/CVE-2026-88914-1.patch: Ensure enough data is available
for reading closed caption boxes in gst/isomp4/qtdemux.c
- debian/patches/CVE-2026-88914-2.patch: Don't try splitting CEA608
samples without known framerate in gst/isomp4/qtdemux.c
- CVE-2026-88914
Date: 2026-09-29 18:34:15.623203+00:00
Changed-By: Kyle Kernick <kyle.kernick at canonical.com>
https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.28.2-2ubuntu0.4
-------------- next part --------------
Sorry, changesfile not available.
More information about the Resolute-changes
mailing list