openSUSE-SU-2026:21877-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21877-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2026:21877-1
Upstream
CVE (26)
Related
Published
2026-09-18T07:48:05Z
Modified
2026-09-25T18:23:10Z
Summary
Security update for ffmpeg-7
Details

This update for ffmpeg-7 fixes the following issues:

  • CVE-2023-6602: HLS Force TTY Demuxer (bsc#1220546).
  • CVE-2023-6604: HLS XBIN Demuxer DoS Amplification (bsc#1220549).
  • CVE-2024-35367: FFmpeg n6.1.1 has an Out-of-bounds Read via libavcodec/ppc/vp8dsp_altivec.c, static const vec_s8 h_subpel_filters_outer (bsc#1234029).
  • CVE-2024-36615: FFmpeg n7.0 has a race condition vulnerability in the VP9 decoder. This could lead to a data race if video encoding parameters were being exported, as the side data would be attached in the decoder thread while (bsc#1234017).
  • CVE-2025-22921: segmentation violation in NULL pointer dereference via the component /libavcodec/jpeg2000dec.c (bsc#1237382).
  • CVE-2026-8461: FFmpeg: Remote code execution via out-of-bounds write in MagicYUV decoder (bsc#1269490).
  • CVE-2026-12706: ffmpeg: heap use-after-free read in RASC decoder decode_move() (bsc#1268595).
  • CVE-2026-58049: incorrect validation in the RASC video decoder can lead to an out-of-bounds heap write and memory corruption (bsc#1269550).
  • CVE-2026-64833: Out-of-Bounds Read via S/PDIF Muxer spdifenc.c (bsc#1272755).
  • CVE-2026-64834: Infinite Loop DoS via RTP/ASF Demuxer (bsc#1272757).
  • CVE-2026-65703: Out-of-Bounds Write in TDSC Video Decoder (bsc#1272759).
  • CVE-2026-65704: Out-of-Bounds Write via TY Demuxer and Shorten Decoder (bsc#1272760).
  • CVE-2026-65705: vf_floodfill Out-of-Bounds Write via filter_frame() (bsc#1272761).
  • CVE-2026-65706: vf_swaprect Out-of-Bounds Write via NV12 Frame Processing (bsc#1272762).
  • CVE-2026-66036: Heap Out-of-Bounds Write in vf_hqdn3d Filter (bsc#1272763).
  • CVE-2026-66037: IAMF Demuxer Uncontrolled Resource Consumption via mix_presentation_obu() (bsc#1272764).
  • CVE-2026-70628: signed integer underflows during subtitle buffer checks can cause heap buffer overflows (bsc#1274268).
  • CVE-2026-70629: unvalidated decompressed frame sizes in video decoders can cause uninitialized heap memory reads (bsc#1274270).
  • CVE-2026-70630: unvalidated decompression sizes in Screenpresso frame decoding can cause uninitialized heap memory reads (bsc#1274282).
  • CVE-2026-70631: unvalidated decompression sizes in TIFF strip decoding can cause uninitialized heap memory reads (bsc#1274287).
  • CVE-2026-70632: unenforced frame dimensions in CineForm HD decoding can cause heap-based out-of-bounds writes (bsc#1274289).
  • CVE-2026-75141: heap buffer overflow in the hvcC box writer (bsc#1276407).
  • CVE-2026-75142: stack buffer overflow in the MPEG-PS muxer (bsc#1276408).
  • CVE-2026-75143: heap buffer overflow in the RIST protocol reader (bsc#1276409).
  • CVE-2026-75144: heap buffer overflow in the VC-2/Dirac RTP packetizer (bsc#1276410).
  • CVE-2026-75146: out-of-bounds read in the DASH demuxer (bsc#1276412).

Changes for ffmpeg-7:

Update to version 7.1.5:

  • Various crash, out-of-bounds access, add boundary check fixes. Affected: .mov parser, DASH parser, Snow encoder, Icecast, RTSP decoder, RV10/RV34 RealVideo, Truespeech, ADPCM, Matroska decoder
  • avcodec/jpeg2000dec: clear array length when freeing it (CVE-2025-22921, bsc#1237382)
  • avcodec/magicyuv: Fix 1 line MEDIAN slices (CVE-2026-8461, bsc#1269490)
  • avcodec/magicyuv: reject slice_height misaligned with chroma vshift.
  • avcodec/magicyuv: Expand the s->interlaced slice-height sanity check.
  • avcodec/rasc: fix heap use-after-free in decode_move(). (CVE-2026-12706, bsc#1268595)
  • avformat/hls: Be more picky on extensions. (CVE-2023-6602, bsc#1220546, CVE-2023-6604, bsc#1220549)
  • lavc/vp9: Fix regression introduced in 0ba0585. It is possible that ff_progress_frame_await() is calledbut ff_progress_frame_report() isn't called when a hardware acceleration method is used, so a thread for vp9 decoding might get stuck. (CVE-2024-36615, bsc#1234017).
  • avcodec/vp9: Fix race when attaching side-data for show-existing frame. (commit: 0ba0585) (CVE-2024-36615, bsc#1234017)
  • lavc/vp9: Fix regression introduced in 0ba0585.
  • avcodec/ppc/vp8dsp_altivec: Fix out-of-bounds access h_subpel_filters_inner[i] and h_subpel_filters_outer[i / 2] belong together and the former allows the range 0..6. (CVE-2024-35367, bsc#1234029)
References

Affected packages

openSUSE:Leap 16.0 / ffmpeg-7

Package

Name
ffmpeg-7
Purl
pkg:rpm/opensuse/ffmpeg-7&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
7.1.5-160000.1.1

Ecosystem specific

{
    "binaries":  [
        {
            "ffmpeg-7":  "7.1.5-160000.1.1",
            "ffmpeg-7-libavcodec-devel":  "7.1.5-160000.1.1",
            "ffmpeg-7-libavdevice-devel":  "7.1.5-160000.1.1",
            "ffmpeg-7-libavfilter-devel":  "7.1.5-160000.1.1",
            "ffmpeg-7-libavformat-devel":  "7.1.5-160000.1.1",
            "ffmpeg-7-libavutil-devel":  "7.1.5-160000.1.1",
            "ffmpeg-7-libpostproc-devel":  "7.1.5-160000.1.1",
            "ffmpeg-7-libswresample-devel":  "7.1.5-160000.1.1",
            "ffmpeg-7-libswscale-devel":  "7.1.5-160000.1.1",
            "libavcodec61":  "7.1.5-160000.1.1",
            "libavdevice61":  "7.1.5-160000.1.1",
            "libavfilter10":  "7.1.5-160000.1.1",
            "libavformat61":  "7.1.5-160000.1.1",
            "libavutil59":  "7.1.5-160000.1.1",
            "libpostproc58":  "7.1.5-160000.1.1",
            "libswresample5":  "7.1.5-160000.1.1",
            "libswscale8":  "7.1.5-160000.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21877-1.json"