Alerts This Week
Warning Icon 1 625
Alerts This Week
Warning Icon 1 625

openSUSE ffmpeg-4 Important Denial of Service Vulnerability 2026-2444-1

opensuse
Calendar Grey June 18, 2026
Dist Opensuse Esm H88
update for ffmpeg-4 addresses important security issues affecting openSUSE. Includes fixes for 11 vulnerabilities.
An update that solves 11 vulnerabilities can now be installed.

Description

This update for ffmpeg-4 fixes the following issues

Update to version 4.4.7:

* CVE-2023-6601: HLS Unsafe File Extension Bypass (bsc#1220545).

* CVE-2024-35366: FFmpeg n6.1.1 is Integer Overflow. The vulnerability exists

in the parse_options function of sbgdec.c within the libavformat module.

When parsing certain options, the software does not adequately validate the

i (bsc#1234030).

* CVE-2025-1594: stack-based buffer overflow in function ff_aac_search_for_tns

of the file libavcodec/aacenc_tns.c of the component AAC Encoder

(bsc#1237561).

* CVE-2025-9951: heap-based buffer overflow in jpeg2000dec (bsc#1249393).

* CVE-2025-10256: NULL pointer dereference in Firequalizer filter

(bsc#1249431).

* CVE-2025-63757: accumulation of filtered pixel values can lead to an integer

overflow (bsc#1255392).

* CVE-2026-30997: Denial of Service via out-of-bounds read (bsc#1262047).

* CVE-2026-40962: inadequate CENC subsample bounds checks can lead to an

...

Read the Full Advisory

Patch

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like

YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

* openSUSE Leap 15.4

zypper in -t patch SUSE-2026-2444=1

* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4

zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2444=1

* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4

zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2444=1

* SUSE Linux Enterprise Server 15 SP4 LTSS

zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2444=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP4

zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2444=1

Package List

* openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586)

* ffmpeg-4-libswscale-devel-4.4.7-150400.3.67.1

* libavfilter7_110-debuginfo-4.4.7-150400.3.67.1

* libavcodec58_134-debuginfo-4.4.7-150400.3.67.1

* libavresample4_0-debuginfo-4.4.7-150400.3.67.1

* libavutil56_70-4.4.7-150400.3.67.1

* libpostproc55_9-4.4.7-150400.3.67.1

* ffmpeg-4-libavutil-devel-4.4.7-150400.3.67.1

* libavdevice58_13-4.4.7-150400.3.67.1

* ffmpeg-4-libavfilter-devel-4.4.7-150400.3.67.1

* ffmpeg-4-libpostproc-devel-4.4.7-150400.3.67.1

* ffmpeg-4-libavformat-devel-4.4.7-150400.3.67.1

* libswresample3_9-4.4.7-150400.3.67.1

* ffmpeg-4-debugsource-4.4.7-150400.3.67.1

* libavformat58_76-4.4.7-150400.3.67.1

* ffmpeg-4-libavcodec-devel-4.4.7-150400.3.67.1

* libavresample4_0-4.4.7-150400.3.67.1

* libswresample3_9-debuginfo-4.4.7-150400.3.67.1

* libavcodec58_134-4.4.7-150400.3.67.1

* libpostproc55_9-debuginfo-4.4.7-150400.3.67.1

* libavformat58_76-debuginfo-4.4.7-150400.3.67.1

* libswscale5_9-4.4.7-150400.3.67.1

*...

Read the Full Advisory

References

* bsc#1220545

* bsc#1234030

* bsc#1237561

* bsc#1249393

* bsc#1249431

* bsc#1255392

* bsc#1262047

* bsc#1262237

## References:

* https://www.suse.com/security/cve/CVE-2023-6601.html

* https://www.suse.com/security/cve/CVE-2024-35366.html

* https://www.suse.com/security/cve/CVE-2024-35368.html

* https://www.suse.com/security/cve/CVE-2024-36618.html

* https://www.suse.com/security/cve/CVE-2025-10256.html

* https://www.suse.com/security/cve/CVE-2025-1594.html

* https://www.suse.com/security/cve/CVE-2025-59728.html

* https://www.suse.com/security/cve/CVE-2025-63757.html

* https://www.suse.com/security/cve/CVE-2025-9951.html

* https://www.suse.com/security/cve/CVE-2026-30997.html

* https://www.suse.com/security/cve/CVE-2026-40962.html

* https://bugzilla.suse.com/show_bug.cgi?id=1220545

* https://bugzilla.suse.com/show_bug.cgi?id=1234030

* https://bugzilla.suse.com/show_bug.cgi?id=1237561

* https://bugzilla.suse.com/show_bug.cgi?id=1249393

* https://bugzilla.suse.com/show_bug.cgi?id=1249431

*...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:2444-1
Release Date: 2026-06-18T08:51:46Z
Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here