[Git][security-tracker-team/security-tracker][master] Add CVE-2026-96611/ffmpeg

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Sep 24 09:43:29 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
bc9f5d5d by Salvatore Bonaccorso at 2026-09-24T10:42:52+02:00
Add CVE-2026-96611/ffmpeg

- - - - -


2 changed files:

- data/CVE/list
- data/DSA/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -119,7 +119,11 @@ CVE-2026-96652 (Plex Media Server before 1.43.3.10861 allows SSRF via '/player/t
 CVE-2026-96651 (Plex Media Server before 1.43.3.10861 builds a file path from the url  ...)
 	NOT-FOR-US: Plex Media Server
 CVE-2026-96611 (FFmpeg before 9.0 has a signed integer overflow in libavformat/mov.c.  ...)
-	TODO: check
+	- ffmpeg 7:8.1.2-1
+	NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23455
+	NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/2cc7b87bdb75bcb59bf8bcd5296ca43f89b3a909 (n9.0)
+	NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/31a192f5dd75be9f7520db29ce44fa8f36ae8ba3 (n8.1.2)
+	NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/15396fa8d550cd19e8619cca919ea09ecbe84ef6 (n7.1.5)
 CVE-2026-96609 (Robur Albatross 1.0.0 through 2.x before 2.7.2 does not limit use of t ...)
 	TODO: check
 CVE-2026-96606 (A security flaw has been discovered in LB-Link BL-CPE600EU 5.8.13. Thi ...)


=====================================
data/DSA/list
=====================================
@@ -442,7 +442,7 @@
 	{CVE-2026-52718 CVE-2026-52719 CVE-2026-53701}
 	[trixie] - gst-plugins-bad1.0 1.26.2-3+deb13u2
 [22 Jun 2026] DSA-6361-1 ffmpeg - security update
-	{CVE-2025-22921 CVE-2026-8461 CVE-2026-30997 CVE-2026-38347 CVE-2026-52296 CVE-2026-52297 CVE-2026-13858}
+	{CVE-2025-22921 CVE-2026-8461 CVE-2026-30997 CVE-2026-38347 CVE-2026-52296 CVE-2026-52297 CVE-2026-13858 CVE-2026-96611}
 	[trixie] - ffmpeg 7:7.1.5-0+deb13u1
 [21 Jun 2026] DSA-6360-1 squid - security update
 	{CVE-2026-33515 CVE-2026-33526 CVE-2026-47729 CVE-2026-50012}



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bc9f5d5d81ba3668738666028aa1d5e9de105a03

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bc9f5d5d81ba3668738666028aa1d5e9de105a03
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260924/93e946a4/attachment.htm>


More information about the debian-security-tracker-commits mailing list