Opened 15 months ago
Closed 15 months ago
#21781 closed enhancement (fixed)
gstreamer gst-plugins-base gst-plugins-good gst-plugins-bad gst-plugins-ugly gst-libav gst-plugins-rs-gstreamer (libgstgtk4) 1.26.3
| Reported by: | Bruce Dubbs | Owned by: | Douglas R. Reno |
|---|---|---|---|
| Priority: | elevated | Milestone: | 12.4 |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
New point version.
Change History (4)
comment:1 by , 15 months ago
| Priority: | normal → elevated |
|---|
comment:2 by , 15 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
I'm grabbing these now, but it will probably be a couple days before I can get to them.
comment:3 by , 15 months ago
Changes:
gstreamer
- aggregator: Do not set event seqnum to INVALID
- baseparse: test: Fix race on test start
- pad: Only remove TAG events on STREAM_START if the stream-id actually changes
- utils: Mark times array as static to avoid symbol conflict with the POSIX function
- vecdeque: Use correct index type gst_vec_deque_drop_struct()
gst-plugins-base
- GstAudioAggregator: fix structure unref in peek_next_sample()
- audioconvert: Fix setting mix-matrix when input caps changes
- encodebasebin: Duplicate encoding profile in property setter
- gl: simplify private gst_gl_gst_meta_api_type_tags_contain_only()
- osxvideosink: Use gst_pad_push_event() and post navigation messages
- playsink: Fix race condition in stream synchronizer pad cleanup during state changes
- python: Fix pulling events from appsink
- streamsynchronizer: Consider streams having received stream-start as waiting
- urisourcebin: Text tracks are no longer set as sparse stream in urisourcebin's multiqueue
gst-plugins-good
- aacparse: Fix counting audio channels in program_config_element
- adaptivedemux2: free cancellable when freeing transfer task
- dashdemux2: Fix seeking in a stream with gaps
- decodebin wavparse cannot pull header
- imagefreeze: fix not negotiate log when stop
- osxvideosink: Use gst_pad_push_event() and post navigation messages
- qml6glsink: Allow configuring if the item will consume input events
- qtmux: Update chunk offsets when converting stco to co64 with faststart
- splitmuxsink: Only send closed message once per open fragment
- rtph265depay: CRA_NUT can also start an (open) GOP
- rtph265depay: fix codec_data generation
- rtspsrc: Don't emit error during close if server is EOF
- twcc: Fix reference timestamp wrapping (again)
- v4l2: Fix possible internal pool leak
- v4l2object: Add support for colorimetry bt2100-pq and 1:4:5:3
- wavparse: Don't error out always when parsing acid chunks
gst-plugins-bad
- amc: Overhaul hw-accelerated video codecs detection
- bayer2rgb: Fix RGB stride calculation
- d3d12compositor: Fix critical warnings
- dashsink: Fix failing test
- decklink: calculate internal using values closer to the current clock times
- decklinkvideosink: show preroll frame correctly
- decklink: clock synchronization after pause
- h266parser: Fix overflow when parsing subpic_level_info
- lcevcdec: Check for errors after receiving all enhanced and base pictures
- meson: fix building -bad tests with disabled soundtouch
- mpegts: handle MPEG2-TS with KLV metadata safely by preventing out of bounds
- mpegtsmux: Corrections around Teletext handling
- srtsink: Fix header buffer filtering
- transcoder: Fix uritranscodebin reference handling
- tsdemux: Allow access unit parsing failures
- tsdemux: Send new-segment before GAP
- vulkanupload: fix regression for uploading VulkanBuffer
- vulkanupload: fix regression when uploading to single memory multiplaned memory images.
- webrtcbin: disconnect signal ICE handlers on dispose
- {d3d12,d3d11}compositor: Fix negative position handling
- {nv,d3d12,d3d11}decoder: Use interlace info in input caps
gst-plugins-ugly
- No changes
GStreamer Rust plugins
- Add new speech synthesis element around ElevenLabs API
- cea708mux: fix another WouldOverflow case
- cea708mux: support configuring a limit to how much data will be pending
- cea708overlay: also reset the output size on flush stop
- gcc: handle out of order packets
- fmp4mux: Fix panic on late GOP
- livekit: expose a connection state property
- mp4mux: add taic box
- mp4mux: test the trak structure
- pcap_writer: Make target-property and pad-path properties writable again
- skia: Don't build skia plugin by default for now
- threadshare: cleanups & usability improvements
- threadshare: sync runtime with latest async-io
- threadshare: fix kqueue reactor
- threadshare: Update to getifaddrs 0.2
- threadshare: add new thread-sharing inter elements
- threadshare: add a ts-rtpdtmfsrc element
- transcriberbin: fix naming of subtitle pads
- tttocea708: don't panic if a new service would overflow
- webrtc: android: Update Gradle and migrate to FindGStreamerMobile
- webrtc: add new examples for stream selection over data channel
- webrtcsrc: the webrtcbin get-transceiver index is not mlineindex
- webrtcsrc: send CustomUpstream events over control channel ..
- webrtcsink: Don't require encoder element for pre-encoded streams
- webrtcsink: Don't reject caps events if the codec_data changes
- whip: server: pick session-id from the endpoint if specified
- cargo: add config file to force CARGO_NET_GIT_FETCH_WITH_CLI=true
- Cargo.lock, deny: Update dependencies and log duplicated targo-lexicon
- Update windows-sys dependency from ">=0.52, <=0.59" to ">=0.52, <=0.60"
- deny: Add override for windows-sys 0.59
- deny: Update lints
- cargo_wrapper: Fix backslashes being parsed as escape codes on Windows
- Fixes for Clock: non-optional return types
- Rename relationmeta plugin to analytics
gst-libav
- No changes
CVE-2025-6663 in gst-plugins-bad: This security vulnerability can allow for manipulating the stack or crashing applications via a stack overflow in the H.266 video parser.
comment:4 by , 15 months ago
| Resolution: | → fixed |
|---|---|
| Status: | assigned → closed |
Fixed at 1f24f1cc911180a2c75b6314bad7a1de61f514cc
SA-12.3-066 issued
Note:
See TracTickets
for help on using tickets.

Marking as elevated for a security fix
I am currently busy responding to issues/release prep with one of the other projects I work with, but I will file the SA as soon as it's done