gpp_maybe Security update for ffmpeg-4
SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-4149


This update for ffmpeg-4 fixes the following issues: - CVE-2026-58049: incorrect validation in the RASC video decoder can lead to an out-of-bounds heap write and memory corruption (bsc#1269550). - CVE-2026-64833: Out-of-Bounds Read via S/PDIF Muxer spdifenc.c (bsc#1272755). - CVE-2026-64834: Infinite Loop DoS via RTP/ASF Demuxer (bsc#1272757). - CVE-2026-65703: Out-of-Bounds Write in TDSC Video Decoder (bsc#1272759). - CVE-2026-65704: Out-of-Bounds Write via TY Demuxer and Shorten Decoder (bsc#1272760). - CVE-2026-65705: vf_floodfill Out-of-Bounds Write via filter_frame() (bsc#1272761). - CVE-2026-65706: vf_swaprect Out-of-Bounds Write via NV12 Frame Processing (bsc#1272762). - CVE-2026-66036: Heap Out-of-Bounds Write in vf_hqdn3d Filter (bsc#1272763). - CVE-2026-70628: signed integer underflows during subtitle buffer checks can cause heap buffer overflows (bsc#1274268). - CVE-2026-70629: unvalidated decompressed frame sizes in video decoders can cause uninitialized heap memory reads (bsc#1274270). - CVE-2026-70630: unvalidated decompression sizes in Screenpresso frame decoding can cause uninitialized heap memory reads (bsc#1274282). - CVE-2026-70631: unvalidated decompression sizes in TIFF strip decoding can cause uninitialized heap memory reads (bsc#1274287). - CVE-2026-70632: unenforced frame dimensions in CineForm HD decoding can cause heap-based out-of-bounds writes (bsc#1274289). - CVE-2026-75142: stack buffer overflow in the MPEG-PS muxer (bsc#1276408). - CVE-2026-75143: heap buffer overflow in the RIST protocol reader (bsc#1276409). - CVE-2026-75144: heap buffer overflow in the VC-2/Dirac RTP packetizer (bsc#1276410). - CVE-2026-75146: out-of-bounds read in the DASH demuxer (bsc#1276412).


cloud_download Downloads

SUSE Package Hub 15.7 s390x
SUSE Package Hub 15.7 aarch64
SUSE Package Hub 15.7 ppc64le
SUSE Package Hub 15.7 x86_64