]>
dgit.raspbian.org Git - gst-plugins-bad1.0.git/log
summary |
shortlog | log |
commit |
commitdiff |
tree
first ⋅ prev ⋅ next
Sebastian Dröge [Tue, 9 Jun 2026 06:40:41 +0000 (09:40 +0300)]
[PATCH] vajpegdecoder: Validate that enough data is available for the current JPEG segment
Gbp-Pq: Name CVE-2026-52719.patch
Sebastian Dröge [Tue, 9 Jun 2026 06:26:38 +0000 (09:26 +0300)]
[PATCH] av1parser: Fix bytes/bits confusion when parsing tile data size
Gbp-Pq: Name CVE-2026-52718.patch
Sebastian Dröge [Wed, 25 Feb 2026 15:22:52 +0000 (17:22 +0200)]
[PATCH] dvbsuboverlay: Mark parsed byte array as const
From
7be5f191f01f3a8e114f4c6e8fb783716f51e98a Mon Sep 17 00:00:00 2001
From: =?UTF-8?q?Sebastian=20Dr=C3=B6ge?= <sebastian@centricular.com>
Date: Wed, 11 Feb 2026 20:45:12 +0200
Subject: [PATCH] dvbsuboverlay: Add missing bounds checks to the parser
everywhere
From
504f965a086ab8cf2d223a1a99d03a71b67458bc Mon Sep 17 00:00:00 2001
From: =?UTF-8?q?Sebastian=20Dr=C3=B6ge?= <sebastian@centricular.com>
Date: Thu, 12 Feb 2026 09:50:23 +0200
Subject: [PATCH] dvbsuboverlay: Avoid integer overflows and unreasonably large
displays/regions
Gbp-Pq: Name CVE-2026-2923.patch
Víctor Manuel Jáquez Leal [Wed, 11 Feb 2026 21:07:49 +0000 (22:07 +0100)]
[PATCH] libs: jpegparser: boundary checks before copying it
Gbp-Pq: Name CVE-2026-3082.patch
Carlos Bentzen [Fri, 20 Feb 2026 16:40:24 +0000 (17:40 +0100)]
[PATCH] h266parser: Fix APS ID bounds check in APS parsing
Gbp-Pq: Name CVE-2026-3086.patch
Carlos Bentzen [Fri, 20 Feb 2026 12:34:50 +0000 (13:34 +0100)]
[PATCH] h266parser: Fix out of bounds write when parsing pic_timing SEI
Gbp-Pq: Name CVE-2026-3081.patch
Carlos Bentzen [Fri, 20 Feb 2026 16:10:04 +0000 (17:10 +0100)]
[PATCH] h266parser: Validate tile index bounds in picture partition parsing
Gbp-Pq: Name CVE-2026-3084.patch
He Junyan [Tue, 24 Jun 2025 13:40:26 +0000 (21:40 +0800)]
[PATCH 1/3] h266parser: Fix overflow when parsing subpic_level_info
1. non_subpic_layers_fraction, ref_level_idc and ref_level_fraction_minus1
fields should not have the GST_H266_MAX_SUBLAYERS limitation.
2. Should check max_sublayers_minus1, no more than GST_H266_MAX_SUBLAYERS-1
Fixes ZDI-CAN-27381, CVE-2025-6663
Closes: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/issues/4503
Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/9295>
Gbp-Pq: Name 0001-h266parser-Fix-overflow-when-parsing-subpic_level_in.patch
Marc Leeman [Tue, 19 Dec 2023 10:59:24 +0000 (11:59 +0100)]
[PATCH] Skip failing tests
camerabin:
https://gitlab.freedesktop.org/gstreamer/gstreamer/-/issues/1244
netsim:
https://gitlab.freedesktop.org/gstreamer/gstreamer/-/issues/3000
Gbp-Pq: Name Skip-failing-tests.patch
Sebastian Dröge [Thu, 17 Jan 2019 15:02:43 +0000 (17:02 +0200)]
opencv data path
Gbp-Pq: Name 02_opencv-data-path.patch
Moritz Mühlenhoff [Sun, 21 Jun 2026 17:35:19 +0000 (19:35 +0200)]
gst-plugins-bad1.0 (1.26.2-3+deb13u2) trixie-security; urgency=medium
* CVE-2026-52718
* CVE-2026-52719
* CVE-2026-53701
[dgit import unpatched gst-plugins-bad1.0 1.26.2-3+deb13u2]
Moritz Mühlenhoff [Sun, 21 Jun 2026 17:35:19 +0000 (19:35 +0200)]
Import gst-plugins-bad1.0_1.26.2-3+deb13u2.debian.tar.xz
[dgit import tarball gst-plugins-bad1.0 1.26.2-3+deb13u2 gst-plugins-bad1.0_1.26.2-3+deb13u2.debian.tar.xz]
Marc Leeman [Fri, 30 May 2025 07:28:42 +0000 (09:28 +0200)]
Import gst-plugins-bad1.0_1.26.2.orig.tar.xz
[dgit import orig gst-plugins-bad1.0_1.26.2.orig.tar.xz]