gpp_maybe Security update for ffmpeg-4
SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-3542


This update for ffmpeg-4 fixes the following issues: Update to release 4.4.8. - CVE-2026-8461: out-of-bounds write in the MagicYUV decoder can lead to denial of service or remote code execution (bsc#1269490). - CVE-2026-12706: heap use-after-free read in the RASC video decoder can lead to denial of service (bsc#1268595). - CVE-2026-64830: heap buffer overflow in the VobSub subtitle demuxer can lead to arbitrary code execution (bsc#1272752). - CVE-2026-64832: double-free in the NVIDIA NVDEC hardware decoder can lead to can lead to memory corruption (bsc#1272754). - CVE-2026-64835: out-of-bounds memory access in the ADX audio decoder can lead to information disclosure and memory corruption (bsc#1272758). - CVE-2026-66038: exposure of uninitialized heap memory by the LCL/ZLIB video decoder can lead to sensitive information disclosure (bsc#1272768). - CVE-2026-66039: signed integer overflow in the MACE6 audio decoder can lead to heap corruption and arbitrary code execution (bsc#1272765). Other updates and bugfixes: - Release 4.4.8 * Various bug fixes to codecs * avcodec/magicyuv: Fix 1 line MEDIAN slices * avcodec/magicyuv: Expand the s->interlaced slice-height sanity check * avcodec/magicyuv: reject slice_height misaligned with chroma vshift


cloud_download Downloads

SUSE Package Hub 15.7 aarch64
SUSE Package Hub 15.7 ppc64le
SUSE Package Hub 15.7 s390x
SUSE Package Hub 15.7 x86_64