| Release | Version |
|---|---|
| bullseye | 1.18.4-3 |
| bookworm | 1.22.0-2 |
| trixie | 1.26.2-1+deb13u1 |
| forky | 1.28.4-1 |
| sid | 1.28.4-1 |
| Bug | bullseye | bookworm | trixie | forky | sid | Description |
|---|---|---|---|---|---|---|
| CVE-2026-12893 | vulnerable (no DSA, postponed) | vulnerable (no DSA, postponed) | vulnerable (no DSA) | fixed | fixed | gstreamer1-libav: gstreamer1-libav: NULL pointer dereference in gstavdemux.c error handler |
| Bug | Description |
|---|---|
| TEMP-0000000-D8C3F4 | stack corruption when handling files with more than 64 audio channels |
| CVE-2026-52717 |
| DSA / DLA | Description |
|---|---|
| DSA-6353-1 | gst-libav1.0 - security update |
| DLA-2644-1 | gst-libav1.0 - security update |
| DSA-4901-1 | gst-libav1.0 - security update |