| Release | Version |
|---|---|
| bookworm | 1.22.0-2+deb12u2 |
| trixie | 1.26.3-4+deb13u1 |
| forky | 1.28.7-1 |
| sid | 1.28.7-1 |
| Bug | bookworm | trixie | forky | sid | Description |
|---|---|---|---|---|---|
| CVE-2026-53704 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | fixed | fixed | A flaw was found in GStreamer's RealMedia demuxer in the gst-plugins-u ... |
| CVE-2026-53703 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | fixed | fixed | A vulnerability was found in the GStreamer RealMedia demuxer (gst-plug ... |
| CVE-2026-19389 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | fixed | fixed | Multiple integer overflow and underflow vulnerabilities were found in ... |
| Bug | Description |
|---|---|
| TEMP-0000000-4DAA44 | out of bounds reads in ASF demuxer |
| CVE-2026-2922 | GStreamer RealMedia Demuxer Out-Of-Bounds Write Remote Code Execution ... |
| CVE-2026-2920 | GStreamer ASF Demuxer Heap-based Buffer Overflow Remote Code Execution ... |
| CVE-2023-38104 | GStreamer RealMedia File Parsing Integer Overflow Remote Code Executio ... |
| CVE-2023-38103 | GStreamer RealMedia File Parsing Integer Overflow Remote Code Executio ... |
| CVE-2017-5847 | The gst_asf_demux_process_ext_content_desc function in gst/asfdemux/gs ... |
| CVE-2017-5846 | The gst_asf_demux_process_ext_stream_props function in gst/asfdemux/gs ... |
| DSA / DLA | Description |
|---|---|
| DSA-6191-1 | gst-plugins-ugly1.0 - security update |
| DLA-4516-1 | gst-plugins-ugly1.0 - security update |
| DLA-3552-1 | gst-plugins-ugly1.0 - security update |
| DSA-5476-1 | gst-plugins-ugly1.0 - security update |
| DLA-2643-1 | gst-plugins-ugly1.0 - security update |
| DSA-4904-1 | gst-plugins-ugly1.0 - security update |
| DSA-3821-1 | gst-plugins-ugly1.0 - security update |