[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index] [SECURITY] [DSA 6359-1] gst-plugins-good1.0 security update To: debian-security-announce@lists.debian.org Subject: [SECURITY] [DSA 6359-1] gst-plugins-good1.0 security update From: Moritz Muehlenhoff <jmm@debian.org> Date: Sun, 21 Jun 2026 17:26:03 +0000 Message-id: <[🔎] ajgeq0MeaV8z7MY6@seger.debian.org> Reply-to: debian-security-announce-request@lists.debian.org -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-6359-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff June 21, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : gst-plugins-good1.0 CVE ID : CVE-2026-1940 CVE-2026-3083 CVE-2026-3085 CVE-2026-39043 CVE-2026-39044 Multiple security vulnerabilities were discovered in plugins for the GStreamer media framework and its codecs and demuxers, which may result in denial of service or potentially the execution of arbitrary code if a malformed media file is opened. For the stable distribution (trixie), these problems have been fixed in version 1.26.2-1+deb13u2. We recommend that you upgrade your gst-plugins-good1.0 packages. For the detailed security status of gst-plugins-good1.0 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/gst-plugins-good1.0 Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmo4HpoACgkQEMKTtsN8 TjbHWRAAjg7TUhFT+JsU91FLuZ2oQ48Rc6dEOPAwtWtQBACoqp1CiY8uHMga7Pwd y/g2R2x6XnaDEljuiQRvNmO2dnBH+iOrf0wYVkj2nL61mudT3aFkI+MJhi7hbkQ5 51q9yympo8L++iHozj2fuGeXpJ0nufgOqVKio5PpJHdVsyGfr/5FROiD6DQ5jOF4 G+3j8KZn2SiEgLZzMLGiFgUX2I0MWuHKwG+ddduP631m3Mv9TQXCNPpaoMQFBVur KEWfEmEM+g3w1NLJLAHOpjX51dhgvPSSW/MfGHeIhKA9JtcGDts+T++DD6tPDbJD wApkaVZ7+yaRBlmrMvUo+4AK7atqC1ZInkd/iYXPxCk695Ql206/4wm7W1VPnVtT 7JNvi7MTamgbbLYnlfH0gX0qJepbQs0v9k0QC/32t240acoSfWghuy2l+4r3NXWA uJrys+X8XRzIoBysWlV56yeECIMZCnJl6Zxjb1fXVA8MOQ+GrKBHA1Pz8qTToxeF wN39yvQ9MW/RtoCveYUbumABlyNiOcfA2I6lDmYpnMvjdyDInd2rA85VA+ftsi1i LxFmfN5zLlVTn0cVh0nW1r4n61ayo68MkRfsDdCd6uWIrpkY7uBN8NUWOXKC+CQ6 /mC/oe/igP2Rsq9Fu4fPQ6GozRUagWuLt9Wyn/Ol9sMVhMHffl4= =p8jI -----END PGP SIGNATURE----- Reply to: debian-security-announce@lists.debian.org Moritz Muehlenhoff (on-list) Moritz Muehlenhoff (off-list) Prev by Date: [SECURITY] [DSA 6358-1] libhttp-daemon-perl security update Next by Date: [SECURITY] [DSA 6360-1] squid security update Previous by thread: [SECURITY] [DSA 6358-1] libhttp-daemon-perl security update Next by thread: [SECURITY] [DSA 6360-1] squid security update Index(es): Date Thread
Multiple vulnerabilities (CVE-2026-1940, CVE-2026-3083, CVE-2026-3085, CVE-2026-39043, CVE-2026-39044) in the GStreamer gst-plugins-good1.0 package could lead to denial of service or arbitrary code execution when processing a malformed media file. The CVSS scores range from 5.1 (MEDIUM) to 8.8 (HIGH). For Debian stable (trixie), the fixed version is 1.26.2-1+deb13u2, while the upstream fixes are in version 1.28.1.