[Git][security-tracker-team/security-tracker][master] new ffmpeg issue
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Wed Sep 2 13:20:08 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
3aa1ef67 by Moritz Muehlenhoff at 2026-09-02T14:19:37+02:00
new ffmpeg issue
- - - - -
2 changed files:
- data/CVE/list
- data/DSA/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1008,7 +1008,13 @@ CVE-2026-53682 (An unauthenticated client can query the Security Domain hosts in
- dogtag-pki <removed>
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2487511
CVE-2026-52295 (Buffer Overflow vulnerability in Ffmpeg v.7.0 and after allows an atta ...)
- TODO: check
+ - ffmpeg 7:8.1.1-1
+ [bookworm] - ffmpeg <not-affected> (Vulnerable code not present)
+ NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/22988
+ NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/016a241102250372a9c2e96f6e8dca67ec01d3f7 (n9.0)
+ NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/d26ce3ec60142eef7d325b5ade4e8f38c6a82015 (n8.1.1)
+ NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/dcba95fb05be76f5b777e94fef4b64a74741aa8a (n7.1.4)
+ NOTE: Introduced by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/4ee05182b7cccfa6928dcb0a45c2b50b7d9ea39b (n7.0)
CVE-2026-52132 (llama.cpp through commit 97f06e9, when started with the --reranking fl ...)
TODO: check
CVE-2026-52131 (llama.cpp b5693 and before has a Reachable Assertion via the gguf_read ...)
=====================================
data/DSA/list
=====================================
@@ -668,7 +668,7 @@
{CVE-2026-6472 CVE-2026-6473 CVE-2026-6474 CVE-2026-6475 CVE-2026-6477 CVE-2026-6478 CVE-2026-6479 CVE-2026-6637}
[bookworm] - postgresql-15 15.18-0+deb12u1
[14 May 2026] DSA-6268-1 ffmpeg - security update
- {CVE-2026-40962 CVE-2026-38343 CVE-2026-38344 CVE-2026-38346 CVE-2026-38348 CVE-2026-38349}
+ {CVE-2026-40962 CVE-2026-38343 CVE-2026-38344 CVE-2026-38346 CVE-2026-38348 CVE-2026-38349 CVE-2026-52295}
[trixie] - ffmpeg 7:7.1.4-0+deb13u1
[14 May 2026] DSA-6267-1 thunderbird - security update
{CVE-2026-8090 CVE-2026-8092 CVE-2026-8094}
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3aa1ef67275e9822ee387d04bb498b4091a9c5aa
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3aa1ef67275e9822ee387d04bb498b4091a9c5aa
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260902/9b258176/attachment.htm>
More information about the debian-security-tracker-commits
mailing list