[Git][security-tracker-team/security-tracker][master] new ffmpeg issue
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Mon Aug 31 14:20:07 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
fc7353d6 by Moritz Muehlenhoff at 2026-08-31T15:19:44+02:00
new ffmpeg issue
- - - - -
2 changed files:
- data/CVE/list
- data/DSA/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -2379,7 +2379,12 @@ CVE-2026-38819 (Multiple memory leaks in openNDS before 11.0.0 allow an unauthen
CVE-2026-38350 (An integer overflow in the target_sws_fuzzer() function (libswscale/ou ...)
TODO: check
CVE-2026-38349 (An integer overflow in the hScale16To19_c() function (libswscale/outpu ...)
- TODO: check
+ - ffmpeg 7:8.1-1
+ NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/issues/21592
+ NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/22369
+ NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1e63151355342228584e30dab2c53a2cb0d19b42 (n8.1)
+ NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/5f9cdf11fc49e41b7a99e2c3f009ef046a9a02d2 (n7.1.4)
+ NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/4425208158170180b0a574c8161247404445b45b (n5.1.9)
CVE-2026-38348 (An integer overflow in the libswscale/utils.c component of FFmpeg N-12 ...)
- ffmpeg 7:8.1-1
NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/issues/21588
=====================================
data/DSA/list
=====================================
@@ -639,7 +639,7 @@
[bookworm] - openjpeg2 2.5.0-2+deb12u3
[trixie] - openjpeg2 2.5.3-2.1~deb13u2
[15 May 2026] DSA-6276-1 ffmpeg - security update
- {CVE-2026-40962 CVE-2026-30997 CVE-2026-38343 CVE-2026-38344 CVE-2026-38346 CVE-2026-38348}
+ {CVE-2026-40962 CVE-2026-30997 CVE-2026-38343 CVE-2026-38344 CVE-2026-38346 CVE-2026-38348 CVE-2026-38349}
[bookworm] - ffmpeg 7:5.1.9-0+deb12u1
[15 May 2026] DSA-6275-1 linux - security update
{CVE-2026-46333}
@@ -665,7 +665,7 @@
{CVE-2026-6472 CVE-2026-6473 CVE-2026-6474 CVE-2026-6475 CVE-2026-6477 CVE-2026-6478 CVE-2026-6479 CVE-2026-6637}
[bookworm] - postgresql-15 15.18-0+deb12u1
[14 May 2026] DSA-6268-1 ffmpeg - security update
- {CVE-2026-40962 CVE-2026-38343 CVE-2026-38344 CVE-2026-38346 CVE-2026-38348}
+ {CVE-2026-40962 CVE-2026-38343 CVE-2026-38344 CVE-2026-38346 CVE-2026-38348 CVE-2026-38349}
[trixie] - ffmpeg 7:7.1.4-0+deb13u1
[14 May 2026] DSA-6267-1 thunderbird - security update
{CVE-2026-8090 CVE-2026-8092 CVE-2026-8094}
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fc7353d650f77fc0226be8bffb1059126867bb98
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fc7353d650f77fc0226be8bffb1059126867bb98
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260831/37733c4e/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list