[Git][security-tracker-team/security-tracker][master] gst-plugins-bad1.0, openjdk-21 DSAs

Moritz Muehlenhoff (@jmm) jmm at debian.org
Fri Aug 21 22:28:04 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
863890b3 by Moritz Mühlenhoff at 2026-08-21T23:27:37+02:00
gst-plugins-bad1.0, openjdk-21 DSAs

- - - - -


3 changed files:

- data/CVE/list
- data/DSA/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -61142,7 +61142,6 @@ CVE-2026-13006 (ACE vulnerability in conditional configuration file processing
 	NOTE: https://logback.qos.ch/news.html#1.5.35
 CVE-2026-12892 (A flaw was found in GStreamer's gst-plugins-bad package. When processi ...)
 	- gst-plugins-bad1.0 1.28.5-1
-	[trixie] - gst-plugins-bad1.0 <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2491321
 	NOTE: https://gstreamer.freedesktop.org/security/sa-2026-0047.html
 	NOTE: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5108 (private)
@@ -61152,7 +61151,6 @@ CVE-2026-12892 (A flaw was found in GStreamer's gst-plugins-bad package. When pr
 	NOTE: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/dfd0be05499d3315b0d125b3be5f06f7ace52259 (1.26 branch)
 CVE-2026-12891 (A flaw was found in the GStreamer gst-plugins-bad package. When proces ...)
 	- gst-plugins-bad1.0 1.28.5-1
-	[trixie] - gst-plugins-bad1.0 <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2491318
 	NOTE: https://gstreamer.freedesktop.org/security/sa-2026-0048.html
 	NOTE: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5109 (private)
@@ -66143,7 +66141,6 @@ CVE-2026-53430 (Improper Handling of Highly Compressed Data (Data Amplification)
 	NOT-FOR-US: elixir-grpc grpc
 CVE-2026-52722 (A signed integer overflow vulnerability was found in GStreamer's VMnc  ...)
 	- gst-plugins-bad1.0 1.28.5-1
-	[trixie] - gst-plugins-bad1.0 <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2486733
 	NOTE: https://gstreamer.freedesktop.org/security/sa-2026-0046.html
 	NOTE: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5107 (private)
@@ -66160,7 +66157,6 @@ CVE-2026-52721 (Multiple out-of-bounds read vulnerabilities were found in GStrea
 	NOTE: Negligible security impact
 CVE-2026-52720 (A heap buffer overflow vulnerability was found in GStreamer's librfb ( ...)
 	- gst-plugins-bad1.0 1.28.5-1
-	[trixie] - gst-plugins-bad1.0 <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2486731
 	NOTE: https://gstreamer.freedesktop.org/security/sa-2026-0043.html
 	NOTE: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5105 (private)


=====================================
data/DSA/list
=====================================
@@ -1,3 +1,9 @@
+[21 Aug 2026] DSA-6458-1 gst-plugins-bad1.0 - security update
+	{CVE-2026-12891 CVE-2026-12892 CVE-2026-19387 CVE-2026-52720 CVE-2026-52722}
+	[trixie] - gst-plugins-bad1.0 1.26.2-3+deb13u3
+[21 Aug 2026] DSA-6457-1 openjdk-21 - security update
+	{CVE-2026-60589 CVE-2026-61308 CVE-2026-70907}
+	[trixie] - openjdk-21 21.0.12.1+1-1~deb13u1
 [21 Aug 2026] DSA-6456-1 spip - security update
 	{CVE-2026-77806}
 	[trixie] - spip 4.4.21+dfsg-0+deb13u1


=====================================
data/dsa-needed.txt
=====================================
@@ -50,8 +50,6 @@ gegl (jmm)
 --
 gimp (jmm)
 --
-gst-plugins-bad1.0 (jmm)
---
 gst-plugins-good1.0
 --
 jackson-databind
@@ -96,8 +94,6 @@ node-dompurify
 --
 openexr
 --
-openjdk-21 (jmm)
---
 openjdk-25 (jmm)
 --
 pacemaker



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/863890b3c6ddb8a779b32549fbb7ac75c9343a19

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/863890b3c6ddb8a779b32549fbb7ac75c9343a19
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260821/078cead4/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list