This update for gstreamer-plugins-bad fixes the following issues:
- CVE-2025-3887: Fixed possible RCE vulnerability via buffer overflow in
H265 Codec Parsing (bsc#1242809).
Patch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.6:
zypper in -t patch openSUSE-2025-229=1
- openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64):
gstreamer-plugins-bad-1.24.0-lp156.3.3.1
gstreamer-plugins-bad-chromaprint-1.24.0-lp156.3.3.1
gstreamer-plugins-bad-chromaprint-debuginfo-1.24.0-lp156.3.3.1
gstreamer-plugins-bad-debuginfo-1.24.0-lp156.3.3.1
gstreamer-plugins-bad-debugsource-1.24.0-lp156.3.3.1
gstreamer-plugins-bad-devel-1.24.0-lp156.3.3.1
gstreamer-plugins-bad-fluidsynth-1.24.0-lp156.3.3.1
gstreamer-plugins-bad-fluidsynth-debuginfo-1.24.0-lp156.3.3.1
gstreamer-transcoder-1.24.0-lp156.3.3.1
gstreamer-transcoder-debuginfo-1.24.0-lp156.3.3.1
gstreamer-transcoder-devel-1.24.0-lp156.3.3.1
libgstadaptivedemux-1_0-0-1.24.0-lp156.3.3.1
libgstadaptivedemux-1_0-0-debuginfo-1.24.0-lp156.3.3.1
libgstanalytics-1_0-0-1.24.0-lp156.3.3.1
libgstanalytics-1_0-0-debuginfo-1.24.0-lp156.3.3.1
libgstbadaudio-1_0-0-1.24.0-lp156.3.3.1
libgstbadaudio-1_0-0-debuginfo-1.24.0-lp156.3.3.1
libgstbasecamerabinsrc-1_0-0-1.24.0-lp156.3.3.1
libgstbasecamerabinsrc-1_0-0-debuginfo-1.24.0-lp156.3.3.1
libgstcodecparse...
Read the Full Advisoryhttps://www.suse.com/security/cve/CVE-2025-3887.html
https://bugzilla.suse.com/1242809
Get the latest Linux and open source security news straight to your inbox.