[ubuntu/questing-updates] gst-plugins-good1.0 1.26.5-1ubuntu2.3 (Accepted)
Ubuntu Archive Robot
ubuntu-archive-robot at lists.canonical.com
Wed May 27 12:58:44 UTC 2026
gst-plugins-good1.0 (1.26.5-1ubuntu2.3) questing-security; urgency=medium
* SECURITY UPDATE: DoS when parsing MP4 audio tracks
- debian/patches/CVE-2026-464xx-1.patch: qtdemux: Avoid division by zero if
0 audio channels are signalled in gst/isomp4/qtdemux.c.
- debian/patches/CVE-2026-464xx-2.patch: qtdemux: Validate chnl defined
layout before using it to index the layouts array in gst/isomp4/qtdemux.c.
- debian/patches/CVE-2026-464xx-3.patch: qtdemux: Avoid out-of-bounds reads
and writes of 64 item audio channel positions array in
gst/isomp4/qtdemux.c.
- debian/patches/CVE-2026-464xx-4.patch: qtdemux: Fix bit pattern check for
omitted audio channels map in gst/isomp4/qtdemux.c.
- CVE-2026-46469
- CVE-2026-46470
Date: 2026-05-24 18:44:18.064489+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
Signed-By: Ubuntu Archive Robot <ubuntu-archive-robot at lists.canonical.com>
https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.26.5-1ubuntu2.3
-------------- next part --------------
Sorry, changesfile not available.
More information about the Questing-changes
mailing list