[Git][security-tracker-team/security-tracker][master] new ffmpeg issue

Moritz Muehlenhoff (@jmm) jmm at debian.org
Mon Aug 31 13:27:57 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
9e6bbdbc by Moritz Muehlenhoff at 2026-08-31T14:27:48+02:00
new ffmpeg issue

- - - - -


2 changed files:

- data/CVE/list
- data/DSA/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -2383,7 +2383,12 @@ CVE-2026-38349 (An integer overflow in the hScale16To19_c() function (libswscale
 CVE-2026-38348 (An integer overflow in the libswscale/utils.c component of FFmpeg N-12 ...)
 	TODO: check
 CVE-2026-38347 (A heap overflow in the ff_sws_alphablendaway function (libswscale/alph ...)
-	TODO: check
+	- ffmpeg 7:8.0.1-2
+	NOTE: https://trac.ffmpeg.org/ticket/11692
+	NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/20063
+	NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/b7946098b19af4f06661213d591a5ed9cd3d26ff (n8.0)
+	NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/bb88e295394e5db584063bde790bfbdba04d54ec (n7.1.5)
+	NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/7ee2f9004bd292cbe98deea3664dc00223d4275c (n5.1.10)
 CVE-2026-38346 (An integer overflow in the yuv2planeX_8_c() function (libswscale/outpu ...)
 	- ffmpeg 7:8.1-1
 	NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/issues/21584


=====================================
data/DSA/list
=====================================
@@ -343,7 +343,7 @@
 	{CVE-2026-52718 CVE-2026-52719 CVE-2026-53701}
 	[trixie] - gst-plugins-bad1.0 1.26.2-3+deb13u2
 [22 Jun 2026] DSA-6361-1 ffmpeg - security update
-	{CVE-2025-22921 CVE-2026-8461 CVE-2026-30997}
+	{CVE-2025-22921 CVE-2026-8461 CVE-2026-30997 CVE-2026-38347}
 	[trixie] - ffmpeg 7:7.1.5-0+deb13u1
 [21 Jun 2026] DSA-6360-1 squid - security update
 	{CVE-2026-33515 CVE-2026-33526 CVE-2026-47729 CVE-2026-50012}



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9e6bbdbc82f510444a353f533093bbc52be7bb9a

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9e6bbdbc82f510444a353f533093bbc52be7bb9a
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260831/dff1ea23/attachment.htm>


More information about the debian-security-tracker-commits mailing list