| Release | Version |
|---|---|
| bullseye | 1.18.4-2+deb11u1 |
| bookworm | 1.22.0-2+deb12u1 |
| trixie | 1.26.3-4 |
| forky | 1.28.1-1 |
| sid | 1.28.1-1 |
| Bug | bullseye | bookworm | trixie | forky | sid | Description |
|---|---|---|---|---|---|---|
| CVE-2026-2922 | vulnerable | vulnerable | vulnerable | fixed | fixed | GStreamer RealMedia Demuxer Out-Of-Bounds Write Remote Code Execution ... |
| CVE-2026-2920 | vulnerable | vulnerable | vulnerable | fixed | fixed | GStreamer ASF Demuxer Heap-based Buffer Overflow Remote Code Execution ... |
| Bug | Description |
|---|---|
| TEMP-0000000-4DAA44 | out of bounds reads in ASF demuxer |
| CVE-2023-38104 | GStreamer RealMedia File Parsing Integer Overflow Remote Code Executio ... |
| CVE-2023-38103 | GStreamer RealMedia File Parsing Integer Overflow Remote Code Executio ... |
| CVE-2017-5847 | The gst_asf_demux_process_ext_content_desc function in gst/asfdemux/gs ... |
| CVE-2017-5846 | The gst_asf_demux_process_ext_stream_props function in gst/asfdemux/gs ... |
| DSA / DLA | Description |
|---|---|
| DLA-3552-1 | gst-plugins-ugly1.0 - security update |
| DSA-5476-1 | gst-plugins-ugly1.0 - security update |
| DLA-2643-1 | gst-plugins-ugly1.0 - security update |
| DSA-4904-1 | gst-plugins-ugly1.0 - security update |
| DSA-3821-1 | gst-plugins-ugly1.0 - security update |