Описание
Security update for gstreamer-plugins-bad
This update for gstreamer-plugins-bad fixes the following issue:
- CVE-2026-52718: byte count instead of a bit count in gst_av1_parser_parse_tile_list_obu() can cause parser desynchronization and an application crash (bsc#1268394).
Список пакетов
openSUSE Leap 16.0
gstreamer-plugins-bad-1.26.7-160000.4.1
gstreamer-plugins-bad-chromaprint-1.26.7-160000.4.1
gstreamer-plugins-bad-devel-1.26.7-160000.4.1
gstreamer-plugins-bad-lang-1.26.7-160000.4.1
gstreamer-transcoder-1.26.7-160000.4.1
gstreamer-transcoder-devel-1.26.7-160000.4.1
libgstadaptivedemux-1_0-0-1.26.7-160000.4.1
libgstanalytics-1_0-0-1.26.7-160000.4.1
libgstbadaudio-1_0-0-1.26.7-160000.4.1
libgstbasecamerabinsrc-1_0-0-1.26.7-160000.4.1
libgstcodecparsers-1_0-0-1.26.7-160000.4.1
libgstcodecs-1_0-0-1.26.7-160000.4.1
libgstcuda-1_0-0-1.26.7-160000.4.1
libgstdxva-1_0-0-1.26.7-160000.4.1
libgstinsertbin-1_0-0-1.26.7-160000.4.1
libgstisoff-1_0-0-1.26.7-160000.4.1
libgstmpegts-1_0-0-1.26.7-160000.4.1
libgstmse-1_0-0-1.26.7-160000.4.1
libgstphotography-1_0-0-1.26.7-160000.4.1
libgstplay-1_0-0-1.26.7-160000.4.1
libgstplayer-1_0-0-1.26.7-160000.4.1
libgstsctp-1_0-0-1.26.7-160000.4.1
libgsttranscoder-1_0-0-1.26.7-160000.4.1
libgsturidownloader-1_0-0-1.26.7-160000.4.1
libgstva-1_0-0-1.26.7-160000.4.1
libgstvulkan-1_0-0-1.26.7-160000.4.1
libgstwayland-1_0-0-1.26.7-160000.4.1
libgstwebrtc-1_0-0-1.26.7-160000.4.1
libgstwebrtcnice-1_0-0-1.26.7-160000.4.1
typelib-1_0-CudaGst-1_0-1.26.7-160000.4.1
typelib-1_0-GstAnalytics-1_0-1.26.7-160000.4.1
typelib-1_0-GstBadAudio-1_0-1.26.7-160000.4.1
typelib-1_0-GstCodecs-1_0-1.26.7-160000.4.1
typelib-1_0-GstCuda-1_0-1.26.7-160000.4.1
typelib-1_0-GstDxva-1_0-1.26.7-160000.4.1
typelib-1_0-GstInsertBin-1_0-1.26.7-160000.4.1
typelib-1_0-GstMpegts-1_0-1.26.7-160000.4.1
typelib-1_0-GstMse-1_0-1.26.7-160000.4.1
typelib-1_0-GstPlay-1_0-1.26.7-160000.4.1
typelib-1_0-GstPlayer-1_0-1.26.7-160000.4.1
typelib-1_0-GstTranscoder-1_0-1.26.7-160000.4.1
typelib-1_0-GstVa-1_0-1.26.7-160000.4.1
typelib-1_0-GstVulkan-1_0-1.26.7-160000.4.1
typelib-1_0-GstVulkanWayland-1_0-1.26.7-160000.4.1
typelib-1_0-GstVulkanXCB-1_0-1.26.7-160000.4.1
typelib-1_0-GstWebRTC-1_0-1.26.7-160000.4.1
Ссылки
- SUSE Security Ratings
- SUSE Bug 1268394
- SUSE CVE CVE-2026-52718 page
Описание
A denial of service vulnerability was found in GStreamer's AV1 codec parser in gst-plugins-bad. The gst_av1_parser_parse_tile_list_obu() function passes a byte count to a bit-reader API that expects a bit count, causing parser desynchronization. A remote attacker could trick a user into opening a specially crafted AV1 media file, triggering an assertion abort and causing the application to crash.
Затронутые продукты
openSUSE Leap 16.0:gstreamer-plugins-bad-1.26.7-160000.4.1
openSUSE Leap 16.0:gstreamer-plugins-bad-chromaprint-1.26.7-160000.4.1
openSUSE Leap 16.0:gstreamer-plugins-bad-devel-1.26.7-160000.4.1
openSUSE Leap 16.0:gstreamer-plugins-bad-lang-1.26.7-160000.4.1
Ссылки
- CVE-2026-52718
- SUSE Bug 1268394