[Git][security-tracker-team/security-tracker][master] new ffmpeg issue
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Mon Aug 31 09:16:20 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
2efbb384 by Moritz Muehlenhoff at 2026-08-31T10:15:04+02:00
new ffmpeg issue
- - - - -
2 changed files:
- data/CVE/list
- data/DSA/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1301,9 +1301,10 @@ CVE-2026-19084 (The shared-files-pro WordPress plugin before 1.7.70 does not val
CVE-2026-18918 (In Eclipse Lyo versions 2.0.0 to 7.0.0, OAuth server authorization che ...)
NOT-FOR-US: Eclipse Lyo
CVE-2026-18393 (A flaw was found in FFmpeg. The tdsc_load_cursor() function writes bey ...)
- - ffmpeg <unfixed>
+ - ffmpeg 7:8.1.2-1
[trixie] - ffmpeg <postponed> (Wait until fixed in 7.1.x upstream branch)
NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/242ff799c75f20bade946314c8d741d0887ee11c (n9.0)
+ NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/031fae5c41e6200d3d9b593339be724857b2aacd (n8.1.1)
CVE-2026-15603 (morgan is an HTTP request logger middleware for Node.js. In versions p ...)
- node-morgan <unfixed>
[trixie] - node-morgan <no-dsa> (Minor issue)
@@ -2381,7 +2382,12 @@ CVE-2026-38345 (A Division-by-Zero vulnerability in the ff_sws_init_single_conte
CVE-2026-38344 (A NULL pointer dereference in the get_min_buffer_size function (/libsw ...)
TODO: check
CVE-2026-38343 (An integer overflow in the libavfilter/vf_scale.c component of FFmpeg ...)
- TODO: check
+ - ffmpeg 7:8.1-1
+ NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/issues/21587
+ NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/22369
+ NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/9adced32785ce11a5923af12d72c25c0c2907e8b (n8.1)
+ NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/90ac66848d11bb36b0f7c7b01553c4a4416945eb (n7.1.4)
+ NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1c4b761bf7a34421e7e8ec5cf6ee8184a912a468 (n5.1.9)
CVE-2026-37198 (An integer overflow in the SMF component of Open5GS v2.7.6 allows atta ...)
- open5gs <itp> (bug #1094791)
CVE-2026-37073 (Incorrect access control in /vfm-admin/ajax/sendfiles.php in Veno File ...)
=====================================
data/DSA/list
=====================================
@@ -639,7 +639,7 @@
[bookworm] - openjpeg2 2.5.0-2+deb12u3
[trixie] - openjpeg2 2.5.3-2.1~deb13u2
[15 May 2026] DSA-6276-1 ffmpeg - security update
- {CVE-2026-40962 CVE-2026-30997}
+ {CVE-2026-40962 CVE-2026-30997 CVE-2026-38343}
[bookworm] - ffmpeg 7:5.1.9-0+deb12u1
[15 May 2026] DSA-6275-1 linux - security update
{CVE-2026-46333}
@@ -665,7 +665,7 @@
{CVE-2026-6472 CVE-2026-6473 CVE-2026-6474 CVE-2026-6475 CVE-2026-6477 CVE-2026-6478 CVE-2026-6479 CVE-2026-6637}
[bookworm] - postgresql-15 15.18-0+deb12u1
[14 May 2026] DSA-6268-1 ffmpeg - security update
- {CVE-2026-40962}
+ {CVE-2026-40962 CVE-2026-38343}
[trixie] - ffmpeg 7:7.1.4-0+deb13u1
[14 May 2026] DSA-6267-1 thunderbird - security update
{CVE-2026-8090 CVE-2026-8092 CVE-2026-8094}
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2efbb38402a3c18763fb2b6a4530f60559ed24c6
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2efbb38402a3c18763fb2b6a4530f60559ed24c6
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260831/7e05e7c6/attachment.htm>
More information about the debian-security-tracker-commits
mailing list