[Git][security-tracker-team/security-tracker][master] Add CVE-2026-30754/ffmpeg

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Sep 12 10:32:43 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
11249c57 by Salvatore Bonaccorso at 2026-09-12T11:32:24+02:00
Add CVE-2026-30754/ffmpeg

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -4856,7 +4856,14 @@ CVE-2026-45219
 CVE-2026-41987 (Permission control vulnerability in the app management module. Impact: ...)
 	NOT-FOR-US: Huawei
 CVE-2026-30754 (A memory corruption vulnerability exists in FFmpeg before 8.1. The RTP ...)
-	TODO: check
+	- ffmpeg 7:8.0.1-2
+	[trixie] - ffmpeg 7:7.1.3-0+deb13u1
+	[bookworm] - ffmpeg 7:5.1.8-0+deb12u1
+	NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/20746
+	NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/d03483bd265b68db00c9b90f6f48dcf61c5c300d (n8.1)
+	NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/8b42ed314af97390cd3269ecfcff79366acb9290 (n8.0.1)
+	NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/ceae7a83532260170b110f954d8ae4d53e0f004a (n7.1.3)
+	NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/b75fcac83c9444884d919b8673591315ec43eb83 (n5.1.8)
 CVE-2026-28659 (In MicroXR Blobstore, there is a possible way to access other app's fi ...)
 	NOT-FOR-US: Android
 CVE-2026-27227 (Adobe Experience Manager is affected by a stored Cross-Site Scripting  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/11249c5722561c8e2192f08c48f0c0da90e80482

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/11249c5722561c8e2192f08c48f0c0da90e80482
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260912/b9cca595/attachment.htm>


More information about the debian-security-tracker-commits mailing list