[Git][security-tracker-team/security-tracker][master] Add CVE-2026-52297/ffmpeg
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Mon Sep 14 13:34:18 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
eb51dbfc by Salvatore Bonaccorso at 2026-09-14T14:25:53+02:00
Add CVE-2026-52297/ffmpeg
- - - - -
2 changed files:
- data/CVE/list
- data/DSA/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -199,7 +199,12 @@ CVE-2026-74933 (The GenieWords WordPress plugin from 1.5.27 to 1.5.34 does not h
CVE-2026-68955 (The installer for Rakuten Kobo Desktop Application (Windows version) i ...)
NOT-FOR-US: installer for Rakuten Kobo Desktop Application (Windows version)
CVE-2026-52297 (FFmpeg before 9.0 has an out-of-bounds read because there is insuffici ...)
- TODO: check
+ - ffmpeg 7:8.1.1-1
+ NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/22988
+ NOTE: Fixed by: https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/8439e0203744a30d280668fcd086f74ed5001da1 (n9.0)
+ NOTE: Fixed by: https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/7d612d27aea2ee7d7de291348bd7f02d64b1988b (n8.1.1)
+ NOTE: Fixed by: https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/ebff1abbad8b036bfc0f52a4785433b06e865e3b (n8.0.2)
+ NOTE: Fixed by: https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/c7a0013d5fedb4a875446a3cd7e6fa9beba4e81a (n7.1.4)
CVE-2026-52296 (FFmpeg before 9.0 has an out-of-bounds read because of missing require ...)
TODO: check
CVE-2026-49030
=====================================
data/DSA/list
=====================================
@@ -397,7 +397,7 @@
{CVE-2026-52718 CVE-2026-52719 CVE-2026-53701}
[trixie] - gst-plugins-bad1.0 1.26.2-3+deb13u2
[22 Jun 2026] DSA-6361-1 ffmpeg - security update
- {CVE-2025-22921 CVE-2026-8461 CVE-2026-30997 CVE-2026-38347}
+ {CVE-2025-22921 CVE-2026-8461 CVE-2026-30997 CVE-2026-38347 CVE-2026-52297}
[trixie] - ffmpeg 7:7.1.5-0+deb13u1
[21 Jun 2026] DSA-6360-1 squid - security update
{CVE-2026-33515 CVE-2026-33526 CVE-2026-47729 CVE-2026-50012}
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/eb51dbfc2e14db7c40a3ec0839a0b010dd515bc6
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/eb51dbfc2e14db7c40a3ec0839a0b010dd515bc6
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260914/6aaf359c/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list