[Git][security-tracker-team/security-tracker][master] new ffmpeg issues

Moritz Muehlenhoff (@jmm) jmm at debian.org
Mon Aug 31 09:43:56 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
f915bf86 by Moritz Muehlenhoff at 2026-08-31T10:43:21+02:00
new ffmpeg issues

- - - - -


2 changed files:

- data/CVE/list
- data/DSA/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -2378,9 +2378,20 @@ CVE-2026-38347 (A heap overflow in the ff_sws_alphablendaway function (libswscal
 CVE-2026-38346 (An integer overflow in the yuv2planeX_8_c() function (libswscale/outpu ...)
 	TODO: check
 CVE-2026-38345 (A Division-by-Zero vulnerability in the ff_sws_init_single_context fun ...)
-	TODO: check
+	- ffmpeg 7:8.1-1
+	[trixie] - ffmpeg <not-affected> (Vulnerable code not present)
+	[bookworm] - ffmpeg <not-affected> (Vulnerable code not present)
+	[bullseye] - ffmpeg <not-affected> (Vulnerable code not present)
+	NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/issues/21585
+	NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/21768
+	NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/04fe98482a264117fa49a166c18227f3f93f921b (n8.1)
 CVE-2026-38344 (A NULL pointer dereference in the get_min_buffer_size function (/libsw ...)
-	TODO: check
+	- ffmpeg 7:8.1-1
+	NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/issues/21583
+	NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/22365
+	NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/dc9bf66796b7c1f4329f127736ddf3258e5ba206 (n8.1)
+	NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/af29ae54a4c9b2d3b3ccb4963f86698c69f28091 (n7.1.4)
+	NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/ea3290bf6e92b0fd905121ee6fbebf1199f8fd24 (n5.1.9)
 CVE-2026-38343 (An integer overflow in the libavfilter/vf_scale.c component of FFmpeg  ...)
 	- ffmpeg 7:8.1-1
 	NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/issues/21587


=====================================
data/DSA/list
=====================================
@@ -639,7 +639,7 @@
 	[bookworm] - openjpeg2 2.5.0-2+deb12u3
 	[trixie] - openjpeg2 2.5.3-2.1~deb13u2
 [15 May 2026] DSA-6276-1 ffmpeg - security update
-	{CVE-2026-40962 CVE-2026-30997 CVE-2026-38343}
+	{CVE-2026-40962 CVE-2026-30997 CVE-2026-38343 CVE-2026-38344}
 	[bookworm] - ffmpeg 7:5.1.9-0+deb12u1
 [15 May 2026] DSA-6275-1 linux - security update
 	{CVE-2026-46333}
@@ -665,7 +665,7 @@
 	{CVE-2026-6472 CVE-2026-6473 CVE-2026-6474 CVE-2026-6475 CVE-2026-6477 CVE-2026-6478 CVE-2026-6479 CVE-2026-6637}
 	[bookworm] - postgresql-15 15.18-0+deb12u1
 [14 May 2026] DSA-6268-1 ffmpeg - security update
-	{CVE-2026-40962 CVE-2026-38343}
+	{CVE-2026-40962 CVE-2026-38343 CVE-2026-38344}
 	[trixie] - ffmpeg 7:7.1.4-0+deb13u1
 [14 May 2026] DSA-6267-1 thunderbird - security update
 	{CVE-2026-8090 CVE-2026-8092 CVE-2026-8094}



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f915bf8678d438c5008b12d5dfdbc9f59cd6bfcb

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f915bf8678d438c5008b12d5dfdbc9f59cd6bfcb
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260831/de2a1fbe/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list