GStreamer is a streaming media framework, based on graphs of elements which
operate on media data.
This package contains plug-ins that aren't tested
well enough, or the code is not of good enough quality.
Update Information:
Backport fix for CVE-2025-3887.
* Fri May 30 2025 Sandro Mani
[ 1 ] Bug #2367931 - CVE-2025-3887 mingw-gstreamer1: GStreamer H265 Codec Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability [fedora-41]
https://bugzilla.redhat.com/show_bug.cgi?id=2367931
[ 2 ] Bug #2367933 - CVE-2025-3887 mingw-gstreamer1: GStreamer H265 Codec Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability [fedora-42]
https://bugzilla.redhat.com/show_bug.cgi?id=2367933
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-96b62e4c87' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
Get the latest Linux and open source security news straight to your inbox.