[ubuntu/questing-security] gst-plugins-good1.0 1.26.5-1ubuntu2.3 (Accepted)

Marc Deslauriers marc.deslauriers at canonical.com
Wed May 27 12:00:48 UTC 2026


gst-plugins-good1.0 (1.26.5-1ubuntu2.3) questing-security; urgency=medium

  * SECURITY UPDATE: DoS when parsing MP4 audio tracks
    - debian/patches/CVE-2026-464xx-1.patch: qtdemux: Avoid division by zero if
      0 audio channels are signalled in gst/isomp4/qtdemux.c.
    - debian/patches/CVE-2026-464xx-2.patch: qtdemux: Validate chnl defined
      layout before using it to index the layouts array in gst/isomp4/qtdemux.c.
    - debian/patches/CVE-2026-464xx-3.patch: qtdemux: Avoid out-of-bounds reads
      and writes of 64 item audio channel positions array in
      gst/isomp4/qtdemux.c.
    - debian/patches/CVE-2026-464xx-4.patch: qtdemux: Fix bit pattern check for
      omitted audio channels map in gst/isomp4/qtdemux.c.
    - CVE-2026-46469
    - CVE-2026-46470

Date: 2026-05-24 18:44:18.064489+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.26.5-1ubuntu2.3
-------------- next part --------------
Sorry, changesfile not available.


More information about the Questing-changes mailing list