Opened 7 months ago

Closed 7 months ago

#22868 closed enhancement (fixed)

gstreamer gst-plugins-base gst-plugins-good gst-plugins-bad gst-plugins-ugly gst-libav gst-plugins-rs-gstreamer 1.28.1

Reported by: Bruce Dubbs Owned by: zeckma
Priority: high Milestone: 13.0
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New point version.

Change History (9)

comment:1 by Joe Locash, 7 months ago

Priority: normal → elevated
 This release only contains bug fixes as well as a number of security fixes. It should be safe to update from 1.28.0, and we recommend you do so at your earliest convenience.

Highlighted bugfixes:
    - Various security fixes and playback fixes
    - Add new whisper-based speech-to-text transcription element
    - Add new debugseimetainserter plugin for testing SEI meta insertion
    - Fix scaling and resizing with UIView on EAGL and Vulkan
    - Reverse playback and gap handling fixes in various components
    - avviddec: Handle field/order changes in mixed interlace mode
    - awstranscriber2: workaround for suspected Rust SDK regression
    - cudaupload, cudadownload: Fix CUDA/GL interop copy path
    - decodebin3: Fix switch to smaller collections and improve collection change on existing pad
    - devenv: Add a subproject for providing the LunarG MoltenVK SDK
    - livesync: fixes and reverse playback handling; ignore upstream latency when upstream is not live
    - objectdetectionoverlay: add support for rotated bounding boxes
    - qml6glsrc: Fix rendering of scene with clipped items
    - speechmatics: allow configuring audio events such as detecting applause, laughter and music
    - livekit webrtc: emit session-requested only for Producer role
    - tsdemux: Fix Continuity Counter handling and handle clock change/resets without skew correction
    - v4l2: Add support for AV1 stateful V4l2 decoder
    - vpxdec: Support downstream pools with alignment requirements
    - vtdec, vtenc: Lots of Apple VideoToolbox decoder and encoder fixes
    - applemedia build improvements, patches for tvOS support, tvos cross file
    - wavpack: Fix handling of format changes, extend parser with new features, handle non-S32 samples
    - webrtcsink: allow specifying custom headers to signalling server
    - webrtcsink: negotiate profile and level for input encoded in H.264
    - webrtcsrc: add request type pads and allow sending encoded data downstream
    - cerbero: wheel: Add a new `gstreamer_meta` package with fewer deps
    - Various bug fixes, build fixes, memory leak fixes, and other stability and reliability improvements

Full release notes: ​https://gstreamer.freedesktop.org/releases/1.28/#1.28.1

comment:2 by Douglas R. Reno, 7 months ago

Priority: elevated → high

Security information:

GStreamer-SA-2026-0001 (CVE-2026-1940): Out-of-bounds read in WAV parser. It is possible for a malicious third party to trigger an out-of-bounds read that can result in a crash of the application.

GStreamer-SA-2026-0002 (No CVE): Out-of-bounds read in MP4 demuxer. It is possible for a malicious third party to trigger an out-of-bounds read that can result in a crash of the application or information leaks.

Note the above impact for information disclosure when reading an MP4 file.

GStreamer-SA-2026-0003 (CVE-2026-3082): Heap-based Buffer Overflow on Huffman tables reading in JPEG parser. It might be possible for a malicious third party to trigger a crash in the application, and possibly also effect code execution through heap manipulation.

The temporary workaround is to not load JPEG files, which really underscores the severity of this one.

GStreamer-SA-2026-0004 (CVE-2026-2921): An integer overflow in the RIFF parser that can cause crashes for certain input files. It is possible for a malicious third party to trigger an integer overflow that can result in out-of-bounds reads and writes to heap memory, and a crash of the application.

GStreamer-SA-2026-0005 (CVE-2026-2922): Out-of-bounds write in RealMedia Demuxer. An out-of-bounds write in the RealMedia demuxer that can cause crashes for certain input files. It is possible for a malicious third party to trigger out-of-bounds writes to heap memory, which can result in a crash of the application.

GStreamer-SA-2026-0006 (CVE-2026-2920): An out-of-bounds write in the ASF demuxer that can cause crashes for certain input files. It is possible for a malicious third party to trigger out-of-bounds writes to heap memory, which can result in a crash of the application.

GStreamer-SA-2026-0007 (CVE-2026-2923): Out-of-bounds read and write in DVB Subtitle Decoder. Various out-of-bounds reads and writes in the DVB subtitle decoder that can cause crashes for certain input files. It is possible for a malicious third party to trigger out-of-bounds reads and writes to heap memory, which can result in a crash of the application.

GStreamer-SA-2026-0008 (CVE-2026-3083, CVE-2026-3085): Multiple vulnerabilities in RTP QDM2 depayloader element. Heap-based buffer overflow and out-of-bounds write in the RTP QDM2 depayloader. It is possible for a malicious third party to trigger a heap overflow or out-of-bounds write that can result in a crash of the application, possibly even remote execution.

Note the possible RCE impact above

GStreamer-SA-2026-0009 (CVE-2026-3086): Out-of-bounds buffer write in H.266 video parser when parsing Adaptation Parameter Set. An out of bounds write in the H.266 video bitstream parser when parsing Adaptation Parameter Sets (APS) can cause crashes for certain input files, and could possibly also allow code execution through stack manipulation. An out of bounds write in the H.266 video bitstream parser when parsing Adaptation Parameter Sets (APS) can cause crashes for certain input files, and could possibly also allow code execution through stack manipulation.

Note above the code execution impact

GStreamer-SA-2026-0010 (CVE-2026-3081): Stack buffer overflow in H.266 video parser when parsing pic_timing SEIs. A stack overflow in the H.266 video bitstream parser when parsing pic_timing SEIs can cause crashes for certain input files, and could possibly also allow code execution through stack manipulation. It is possible for a malicious third party to trigger a buffer overflow that can result in a crash of the application and possibly also allow code execution through stack manipulation.

Note above the code execution impact

GStreamer-SA-2026-0011 (CVE-2026-3084): Out-of-bounds write in H.266 video parser when parsing picture partitions. It is possible for a malicious third party to trigger a buffer overflow that can result in a crash of the application and possibly also allow code execution through stack manipulation.

Note above the code execution impact

GStreamer-SA-2026-0012 (No CVE): H.265 video parser potential denial-of-service. A missing bounds check in the H.265 video parser could cause a crash for certain malformed input files through memory exhaustion. It is possible for a malicious third party to trigger a crash of the application through a specially-crafted input file.

Rating as high due to the information disclosure and RCE impacts.

Upstream also telling users to just... not load JPEG files if the patch isn't applied isn't ideal.

comment:3 by Bruce Dubbs, 7 months ago

Milestone: 13.1 → 13.0

comment:4 by Joe Locash, 7 months ago

Owner: changed from blfs-book to Joe Locash
Status: new → assigned

comment:5 by Joe Locash, 7 months ago

Fixed at 0f3b577395.

Leaving open for SA.

comment:6 by zeckma, 7 months ago

I'll handle the SA.

comment:7 by Bruce Dubbs, 7 months ago

Owner: changed from Joe Locash to zeckma
Status: assigned → new

comment:8 by zeckma, 7 months ago

Status: new → assigned

SA-12.4-109 issued.

comment:9 by zeckma, 7 months ago

Resolution: → fixed
Status: assigned → closed
Note: See TracTickets for help on using tickets.