- What: Security update for gst-plugins-bad1.0 in Debian
- Impact: Addresses multiple vulnerabilities in GStreamer media plugins
[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index] [SECURITY] [DSA 6458-1] gst-plugins-bad1.0 security update To: debian-security-announce@lists.debian.org Subject: [SECURITY] [DSA 6458-1] gst-plugins-bad1.0 security update From: Moritz Muehlenhoff <jmm@debian.org> Date: Fri, 21 Aug 2026 21:30:32 +0000 Message-id: <[🔎] aojDeD_DMkyXmeuC@seger.debian.org> Reply-to: debian-security-announce-request@lists.debian.org -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-6458-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff August 21, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : gst-plugins-bad1.0 CVE ID : CVE-2026-12891 CVE-2026-12892 CVE-2026-19387 CVE-2026-52720 CVE-2026-52722 Multiple security vulnerabilities were discovered in plugins for the GStreamer media framework and its codecs and demuxers, which may result in denial of service or potentially the execution of arbitrary code if a malformed media file is opened. For the stable distribution (trixie), these problems have been fixed in version 1.26.2-3+deb13u3. We recommend that you upgrade your gst-plugins-bad1.0 packages. For the detailed security status of gst-plugins-bad1.0 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/gst-plugins-bad1.0 Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmqIwxQACgkQEMKTtsN8 TjYjAA//WLrsGxFkmztPEifwnoVmH0qU0st4Va7b1+wvq1X1uSvYNV8OrYDVbrzN fP9Izr0g96bq/jNKeMm07M5maCO/v2MSqtMopMP5Yr5naZ7a7mquftEpa1kF5tN9 lsTImTALzeLm3RnW/8rDpHm+jYJAK2xJ+Xl1wlVaokhBFG06PPpJij2m95v8RFXn 1Tm3an7SMRgAKJaeL/h0psqhlZgTJWaHayVTEngEMc0CmYoHIOSkaNLq2GMVxAOq vT40qvFIpiXPYIKHlxOrfYQ3opTTQajCky0dpqiA2yrLx72WGyDwV0ed+ir3QoTC 2kJF9akch5wYL7Ix5Vxh68lmulNMrwL0/jszIM1qg+yA20pNr2KOkCRp7OdhSkhE lS6v3V2vDFPNhLM99WWwb6pkUNpfI8YpCx5ixp7NuKnq8MKvDrDugtXF8DgM6UJp dPGqUzP63dV7xTt2vAo96lSY0XfjnH0gp8t+lfvD+k5Q1+xrczmfg12c/f85NzED cWpOH6ZqdFu2o97DFbiKWL01GNRhW7kweBMVGS5R/ou6+A2ikGxzmunspcIUETt7 KoU6HSNOS70iZKuxiLE8mIMIzMBbn4+mxyaRul3nPUv06phAJYFdM8I8rKbeRUhx hj+JkcddtU+ccNTWlu9qnuThPQihHq4luvJKHC9NPxMxnMmtixQ= =TiiT -----END PGP SIGNATURE----- Reply to: debian-security-announce@lists.debian.org Moritz Muehlenhoff (on-list) Moritz Muehlenhoff (off-list) Prev by Date: [SECURITY] [DSA 6457-1] openjdk-21 security update Previous by thread: [SECURITY] [DSA 6457-1] openjdk-21 security update Index(es): Date Thread