[Git][security-tracker-team/security-tracker][master] more ffmpeg issues fixed in sid

Moritz Muehlenhoff (@jmm) jmm at debian.org
Sun Sep 20 13:38:50 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
c6cb9d6f by Moritz Muehlenhoff at 2026-09-20T14:38:28+02:00
more ffmpeg issues fixed in sid

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -70603,25 +70603,29 @@ CVE-2026-66138 (In OpenStack Ironic Python Agent through 11.6.0, aproject-scoped
 	NOTE: https://www.openwall.com/lists/oss-security/2026/07/23/5
 	NOTE: https://bugs.launchpad.net/ironic-python-agent/+bug/2160050
 CVE-2026-65706 (FFmpeg versions 3.0 through 8.1.2 contain an out-of-bounds write vulne ...)
-	- ffmpeg <unfixed>
+	- ffmpeg 7:9.0.2-1
 	[trixie] - ffmpeg <postponed> (Wait until fixed in 7.1.x upstream branch)
 	NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23779
-	NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a7e38b617b32f996beaa371bbf04b39907d7a527
+	NOTE: Fixed by https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a7e38b617b32f996beaa371bbf04b39907d7a527 (master)
+	NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/b3c7ebc1edc401fd9881277fdfae93f3f24ceb81 (n9.0)
 CVE-2026-65705 (FFmpeg versions 3.4 through 8.1.2 contain an out-of-bounds write vulne ...)
-	- ffmpeg <unfixed>
+	- ffmpeg 7:9.0.2-1
 	[trixie] - ffmpeg <postponed> (Wait until fixed in 7.1.x upstream branch)
 	NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23780
-	NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/f186c50cf53aec20e9a29059cb22ca3f2d59201c
+	NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/f186c50cf53aec20e9a29059cb22ca3f2d59201c (master)
+	NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/30a52276f9dff60fe732d8bb8d463e587ff69c94 (n9.0)
 CVE-2026-65704 (FFmpeg through 8.1.2 contains an out-of-bounds write vulnerability tha ...)
-	- ffmpeg <unfixed>
+	- ffmpeg 7:9.0.2-1
 	[trixie] - ffmpeg <postponed> (Wait until fixed in 7.1.x upstream branch)
 	NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23767
-	NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/de771bd52774a52d45b0e2c82e56995a1ef40df7
+	NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/de771bd52774a52d45b0e2c82e56995a1ef40df7 (master)
+	NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/52f7983f15678c8a6065327760d7b6eb1c9c84ed (n9.0)
 CVE-2026-65703 (FFmpeg versions 2.7 through 8.1.2 contain an out-of-bounds write vulne ...)
-	- ffmpeg <unfixed>
+	- ffmpeg 7:9.0.2-1
 	[trixie] - ffmpeg <postponed> (Wait until fixed in 7.1.x upstream branch)
 	NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23773
-	NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/fd3ee52fab34d98a95b787d0b5ff45685766200c
+	NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/fd3ee52fab34d98a95b787d0b5ff45685766200c (master)
+	NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/3b85fbe89025ea696988488358dfde41a09c53c5 (n9.0)
 CVE-2026-65694 (Microweber CMS through 2.0.20 contains a path traversal vulnerability  ...)
 	NOT-FOR-US: Microweber CMS
 CVE-2026-65604 (Skipper contains an incomplete fix for CVE-2026-50197 in which oversiz ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c6cb9d6f012e6f91c4663deca0712b6f314d7b46

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c6cb9d6f012e6f91c4663deca0712b6f314d7b46
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260920/6b8d43d8/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list