Re: [BLFS Trac] #23285: gstreamer gst-plugins-base gst-plugins-good gst-plugins-bad gst-plugins-ugly gst-libav gst-plugins-rs-gstreamer 1.28.3
| Newsgroups | gmane.linux.lfs.beyond.book |
|---|---|
| Message-ID | <[email protected]> |
#23285: gstreamer gst-plugins-base gst-plugins-good gst-plugins-bad gst-plugins-
ugly gst-libav gst-plugins-rs-gstreamer 1.28.3
-------------------------+------------------------
Reporter: Bruce Dubbs | Owner: blfs-book
Type: enhancement | Status: new
Priority: high | Milestone: 13.1
Component: BOOK | Version: git
Severity: normal | Resolution:
Keywords: |
-------------------------+------------------------
Changes (by Douglas R. Reno):
* priority: normal => high
Comment:
The GStreamer Security Center reports the following vulnerabilities fixed:
- GStreamer-SA-2026-0024: Out-of-bounds reads in MPEG PS PES header
parsing. "A malicious third party could trigger out-of-bounds reads when
processing malicious MPEG Program Stream files, resulting in application
crashes and denial of service. Information disclosure is also possible as
sensitive memory contents could be exposed."
- GStreamer-SA-2026-0025: Insufficient validation in MOV/MP4 demuxer
uncompressed video handling. "A malicious third party could trigger a
crash or denial of service by providing a crafted MOV/MP4 file with
invalid uncompressed video parameters."
- GStreamer-SA-2026-0026: Out-of-bounds write in H.266/VVC parser when
parsing PPS tile slices. "A malicious third party could trigger an out-of-
bounds write by providing a crafted H.266/VVC video stream with invalid
tile slice configuration, potentially resulting in a crash, data
corruption, or arbitrary code execution."
- GStreamer-SA-2026-0027: Out-of-bounds read in MXF demuxer temporal
offset check. "A malicious third party could trigger an out-of-bounds read
by providing a crafted MXF file with invalid temporal offset values,
potentially resulting in a crash or denial of service. Information
disclosure is also possible as sensitive memory contents could be
exposed."
- GStreamer-SA-2026-0028: Use-after-free in GStreamer core buffer value
deserialization. "A malicious third party could trigger a use-after-free
by providing crafted data containing serialized buffer values with invalid
content, potentially resulting in a crash, data corruption, or arbitrary
code execution."
- GStreamer-SA-2026-0029: Bounds check errors in MXF VANC packet
handling."A malicious third party could trigger out-of-bounds reads or
incorrect buffer operations by providing a crafted MXF file with invalid
VANC packet configuration, potentially resulting in a crash, data
corruption, or denial of service."
Arbitrary code execution and data corruption via any program that uses
gstreamer is pretty serious (SA-2026-0028 is in the core gstreamer package
itself)
--
Ticket URL: <https://wiki.linuxfromscratch.org/blfs/ticket/23285#comment:1>
BLFS Trac <https://wiki.linuxfromscratch.org/blfs/>
Beyond Linux From Scratch
--
http://lists.linuxfromscratch.org/sympa/info/blfs-book
Unsubscribe: See the above information page