Home / mailingsPDF  

[SECURITY] [DSA 6458-1] gst-plugins-bad1.0 security update

Posted on 21 August 2026
Debian Security Advisory

- -------------------------------------------------------------------------
Debian Security Advisory DSA-6458-1 security@debian.org
https://www.debian.org/security/ Moritz Muehlenhoff
August 21, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : gst-plugins-bad1.0
CVE ID : CVE-2026-12891 CVE-2026-12892 CVE-2026-19387
CVE-2026-52720 CVE-2026-52722

Multiple security vulnerabilities were discovered in plugins for
the GStreamer media framework and its codecs and demuxers, which
may result in denial of service or potentially the execution of
arbitrary code if a malformed media file is opened.

For the stable distribution (trixie), these problems have been fixed in
version 1.26.2-3+deb13u3.

We recommend that you upgrade your gst-plugins-bad1.0 packages.

For the detailed security status of gst-plugins-bad1.0 please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/gst-plugins-bad1.0

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org

 

TOP