SUSE-SU-2026:2444-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20262444-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2444-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:2444-1
Upstream
CVE (11)
Related
Published
2026-06-18T08:51:46Z
Modified
2026-06-19T08:15:05Z
Summary
Security update for ffmpeg-4
Details

This update for ffmpeg-4 fixes the following issues

Update to version 4.4.7:

  • CVE-2023-6601: HLS Unsafe File Extension Bypass (bsc#1220545).
  • CVE-2024-35366: FFmpeg n6.1.1 is Integer Overflow. The vulnerability exists in the parse_options function of sbgdec.c within the libavformat module. When parsing certain options, the software does not adequately validate the i (bsc#1234030).
  • CVE-2025-1594: stack-based buffer overflow in function ff_aac_search_for_tns of the file libavcodec/aacenc_tns.c of the component AAC Encoder (bsc#1237561).
  • CVE-2025-9951: heap-based buffer overflow in jpeg2000dec (bsc#1249393).
  • CVE-2025-10256: NULL pointer dereference in Firequalizer filter (bsc#1249431).
  • CVE-2025-63757: accumulation of filtered pixel values can lead to an integer overflow (bsc#1255392).
  • CVE-2026-30997: Denial of Service via out-of-bounds read (bsc#1262047).
  • CVE-2026-40962: inadequate CENC subsample bounds checks can lead to an integer overflow (bsc#1262237).
References

Affected packages

SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS
ffmpeg-4

Package

Name
ffmpeg-4
Purl
pkg:rpm/suse/ffmpeg-4&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4.4.7-150400.3.67.1

Ecosystem specific

{
    "binaries":  [
        {
            "libavcodec58_134":  "4.4.7-150400.3.67.1",
            "libavformat58_76":  "4.4.7-150400.3.67.1",
            "libavutil56_70":  "4.4.7-150400.3.67.1",
            "libpostproc55_9":  "4.4.7-150400.3.67.1",
            "libswresample3_9":  "4.4.7-150400.3.67.1",
            "libswscale5_9":  "4.4.7-150400.3.67.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2444-1.json"
SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS
ffmpeg-4

Package

Name
ffmpeg-4
Purl
pkg:rpm/suse/ffmpeg-4&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4.4.7-150400.3.67.1

Ecosystem specific

{
    "binaries":  [
        {
            "libavcodec58_134":  "4.4.7-150400.3.67.1",
            "libavformat58_76":  "4.4.7-150400.3.67.1",
            "libavutil56_70":  "4.4.7-150400.3.67.1",
            "libpostproc55_9":  "4.4.7-150400.3.67.1",
            "libswresample3_9":  "4.4.7-150400.3.67.1",
            "libswscale5_9":  "4.4.7-150400.3.67.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2444-1.json"
SUSE:Linux Enterprise Server 15 SP4-LTSS
ffmpeg-4

Package

Name
ffmpeg-4
Purl
pkg:rpm/suse/ffmpeg-4&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4.4.7-150400.3.67.1

Ecosystem specific

{
    "binaries":  [
        {
            "libavcodec58_134":  "4.4.7-150400.3.67.1",
            "libavformat58_76":  "4.4.7-150400.3.67.1",
            "libavutil56_70":  "4.4.7-150400.3.67.1",
            "libpostproc55_9":  "4.4.7-150400.3.67.1",
            "libswresample3_9":  "4.4.7-150400.3.67.1",
            "libswscale5_9":  "4.4.7-150400.3.67.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2444-1.json"
SUSE:Linux Enterprise Server for SAP Applications 15 SP4
ffmpeg-4

Package

Name
ffmpeg-4
Purl
pkg:rpm/suse/ffmpeg-4&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4.4.7-150400.3.67.1

Ecosystem specific

{
    "binaries":  [
        {
            "libavcodec58_134":  "4.4.7-150400.3.67.1",
            "libavformat58_76":  "4.4.7-150400.3.67.1",
            "libavutil56_70":  "4.4.7-150400.3.67.1",
            "libpostproc55_9":  "4.4.7-150400.3.67.1",
            "libswresample3_9":  "4.4.7-150400.3.67.1",
            "libswscale5_9":  "4.4.7-150400.3.67.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2444-1.json"