[Git][security-tracker-team/security-tracker][master] new ffmpeg issue

Moritz Muehlenhoff (@jmm) jmm at debian.org
Wed Sep 2 13:20:08 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
3aa1ef67 by Moritz Muehlenhoff at 2026-09-02T14:19:37+02:00
new ffmpeg issue

- - - - -


2 changed files:

- data/CVE/list
- data/DSA/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1008,7 +1008,13 @@ CVE-2026-53682 (An unauthenticated client can query the Security Domain hosts in
 	- dogtag-pki <removed>
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2487511
 CVE-2026-52295 (Buffer Overflow vulnerability in Ffmpeg v.7.0 and after allows an atta ...)
-	TODO: check
+	- ffmpeg 7:8.1.1-1
+	[bookworm] - ffmpeg <not-affected> (Vulnerable code not present)
+	NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/22988
+	NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/016a241102250372a9c2e96f6e8dca67ec01d3f7 (n9.0)
+	NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/d26ce3ec60142eef7d325b5ade4e8f38c6a82015 (n8.1.1)
+	NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/dcba95fb05be76f5b777e94fef4b64a74741aa8a (n7.1.4)
+	NOTE: Introduced by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/4ee05182b7cccfa6928dcb0a45c2b50b7d9ea39b (n7.0)
 CVE-2026-52132 (llama.cpp through commit 97f06e9, when started with the --reranking fl ...)
 	TODO: check
 CVE-2026-52131 (llama.cpp b5693 and before has a Reachable Assertion via the gguf_read ...)


=====================================
data/DSA/list
=====================================
@@ -668,7 +668,7 @@
 	{CVE-2026-6472 CVE-2026-6473 CVE-2026-6474 CVE-2026-6475 CVE-2026-6477 CVE-2026-6478 CVE-2026-6479 CVE-2026-6637}
 	[bookworm] - postgresql-15 15.18-0+deb12u1
 [14 May 2026] DSA-6268-1 ffmpeg - security update
-	{CVE-2026-40962 CVE-2026-38343 CVE-2026-38344 CVE-2026-38346 CVE-2026-38348 CVE-2026-38349}
+	{CVE-2026-40962 CVE-2026-38343 CVE-2026-38344 CVE-2026-38346 CVE-2026-38348 CVE-2026-38349 CVE-2026-52295}
 	[trixie] - ffmpeg 7:7.1.4-0+deb13u1
 [14 May 2026] DSA-6267-1 thunderbird - security update
 	{CVE-2026-8090 CVE-2026-8092 CVE-2026-8094}



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3aa1ef67275e9822ee387d04bb498b4091a9c5aa

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3aa1ef67275e9822ee387d04bb498b4091a9c5aa
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260902/9b258176/attachment.htm>


More information about the debian-security-tracker-commits mailing list