Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 595
Alerts This Week
Warning Icon 1 595

openSUSE gstreamer-plugins-bad Important Buffer Overflow Issues 2026-3125-1

opensuse
Calendar Grey July 20, 2026
Scroller Opensuse
An important update for openSUSE addresses multiple vulnerabilities in gstreamer-plugins-bad, ensuring better security.
An update that solves seven vulnerabilities can now be installed.

Description

This update for gstreamer-plugins-bad fixes the following issues:

* CVE-2026-12892: 1-byte heap out-of-bounds read in H.264 NAL extension slice

parser (bsc#1268971).

* CVE-2026-14935: webrtcbin accepts remote SDP without a=fingerprint due to

inverted presence check (bsc#1271051).

* CVE-2026-52720: invalid check of total area instead of individual dimensions

could trigger a heap out-of-bounds write (bsc#1268406).

* CVE-2026-52721: crafted PCAP records during IPv4 or TCP header parsing could

cause an out-of-bounds read (bsc#1268408).

* CVE-2026-52722: crafted VMnc stream with large cursor dimensions can

overflow signed integer (bsc#1268410).

* CVE-2026-53702: incorrect loop bound during H.265 SEI message parsing could

result in a stack buffer overflow (bsc#1268168).

* CVE-2026-59692: unvalidated peer certificate Subject DN printed during a

DTLS handshake could cause a stack buffer overflow (bsc#1271168).

Patch

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like

YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise Server for SAP Applications 15 SP5

zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3125=1

* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5

zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3125=1

* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5

zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3125=1

* SUSE Linux Enterprise Server 15 SP5 LTSS

zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3125=1

* openSUSE Leap 15.5

zypper in -t patch SUSE-2026-3125=1

Package List

* SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64)

* typelib-1_0-GstInsertBin-1_0-1.22.0-150500.3.34.1

* libgstcuda-1_0-0-debuginfo-1.22.0-150500.3.34.1

* libgstsctp-1_0-0-1.22.0-150500.3.34.1

* libgstphotography-1_0-0-1.22.0-150500.3.34.1

* libgstmpegts-1_0-0-1.22.0-150500.3.34.1

* typelib-1_0-GstPlay-1_0-1.22.0-150500.3.34.1

* libgstcodecs-1_0-0-1.22.0-150500.3.34.1

* gstreamer-plugins-bad-chromaprint-1.22.0-150500.3.34.1

* libgstplay-1_0-0-debuginfo-1.22.0-150500.3.34.1

* libgsttranscoder-1_0-0-debuginfo-1.22.0-150500.3.34.1

* libgstcodecparsers-1_0-0-1.22.0-150500.3.34.1

* typelib-1_0-GstCuda-1_0-1.22.0-150500.3.34.1

* libgstinsertbin-1_0-0-debuginfo-1.22.0-150500.3.34.1

* libgstbasecamerabinsrc-1_0-0-debuginfo-1.22.0-150500.3.34.1

* libgstsctp-1_0-0-debuginfo-1.22.0-150500.3.34.1

* libgstwayland-1_0-0-1.22.0-150500.3.34.1

* typelib-1_0-GstCodecs-1_0-1.22.0-150500.3.34.1

* gstreamer-plugins-bad-chromaprint-debuginfo-1.22.0-150500.3.34.1

*...

Read the Full Advisory

References

* bsc#1268168

* bsc#1268406

* bsc#1268408

* bsc#1268410

* bsc#1268971

* bsc#1271051

* bsc#1271168

## References:

* https://www.suse.com/security/cve/CVE-2026-12892.html

* https://www.suse.com/security/cve/CVE-2026-14935.html

* https://www.suse.com/security/cve/CVE-2026-52720.html

* https://www.suse.com/security/cve/CVE-2026-52721.html

* https://www.suse.com/security/cve/CVE-2026-52722.html

* https://www.suse.com/security/cve/CVE-2026-53702.html

* https://www.suse.com/security/cve/CVE-2026-59692.html

* https://bugzilla.suse.com/show_bug.cgi?id=1268168

* https://bugzilla.suse.com/show_bug.cgi?id=1268406

* https://bugzilla.suse.com/show_bug.cgi?id=1268408

* https://bugzilla.suse.com/show_bug.cgi?id=1268410

* https://bugzilla.suse.com/show_bug.cgi?id=1268971

* https://bugzilla.suse.com/show_bug.cgi?id=1271051

* https://bugzilla.suse.com/show_bug.cgi?id=1271168

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:3125-1
Release Date: 2026-07-20T07:01:47Z
Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP5

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.