[Git][security-tracker-team/security-tracker][master] Add CVE-2026-52296/ffmpeg

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Sep 14 13:55:15 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
c396c5cb by Salvatore Bonaccorso at 2026-09-14T14:54:35+02:00
Add CVE-2026-52296/ffmpeg

- - - - -


2 changed files:

- data/CVE/list
- data/DSA/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -206,7 +206,12 @@ CVE-2026-52297 (FFmpeg before 9.0 has an out-of-bounds read because there is ins
 	NOTE: Fixed by: https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/ebff1abbad8b036bfc0f52a4785433b06e865e3b (n8.0.2)
 	NOTE: Fixed by: https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/c7a0013d5fedb4a875446a3cd7e6fa9beba4e81a (n7.1.4)
 CVE-2026-52296 (FFmpeg before 9.0 has an out-of-bounds read because of missing require ...)
-	TODO: check
+	- ffmpeg 7:8.1.1-1
+	NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/22988
+	NOTE: Fixed by: https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/23227a444de4a8f7696f46660cdd044b460f7e47 (n9.0)
+	NOTE: Fixed by: https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/d1b0069077fad943387d113322c058b3e06d0c01 (n8.1.1)
+	NOTE: Fixed by: https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/d18354f8d4bd018eb486d18079ff0afb3b84c506 (n8.0.2)
+	NOTE: Fixed by: https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/2437ca465fea26d141fe02e17bfa2d52468ab988 (n7.1.4)
 CVE-2026-49030
 	REJECTED
 CVE-2026-38924 (In Oraios AI Serena before 1.0.0, the listen address of the MCP server ...)


=====================================
data/DSA/list
=====================================
@@ -397,7 +397,7 @@
 	{CVE-2026-52718 CVE-2026-52719 CVE-2026-53701}
 	[trixie] - gst-plugins-bad1.0 1.26.2-3+deb13u2
 [22 Jun 2026] DSA-6361-1 ffmpeg - security update
-	{CVE-2025-22921 CVE-2026-8461 CVE-2026-30997 CVE-2026-38347 CVE-2026-52297}
+	{CVE-2025-22921 CVE-2026-8461 CVE-2026-30997 CVE-2026-38347 CVE-2026-52296 CVE-2026-52297}
 	[trixie] - ffmpeg 7:7.1.5-0+deb13u1
 [21 Jun 2026] DSA-6360-1 squid - security update
 	{CVE-2026-33515 CVE-2026-33526 CVE-2026-47729 CVE-2026-50012}



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c396c5cb50aa06a0251ac5c888a71af806a4b39c

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c396c5cb50aa06a0251ac5c888a71af806a4b39c
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260914/ae259935/attachment.htm>


More information about the debian-security-tracker-commits mailing list