GStreamer plugins with good code and licensing
Backport upstream commit 93fa4cd30ba43b38b02a9de76a7a80dc198c87a0
(qtmoovrecover: Validate box sizes) to fix CVE-2026-18295 and
CVE-2026-18296. The patch adds box size validation and box version
checks to gst/isomp4/atomsrecovery.c. The upstream patch was adapted
from the GStreamer monorepo layout to match the standalone
gst-plugins-good-1.16.1 source tree.
CVE: CVE-2026-18295 CVE-2026-18296
Upstream patches:
-
|
||
|---|---|---|
| .gitignore | ||
| 0001-matroskademux-Fix-extraction-of-multichannel-WavPack.patch | ||
| 0001-rtpqdm2depay-error-out-if-anyone-tries-to-use-this-e.patch | ||
| 0002-matroskademux-Initialize-track-context-out-parameter.patch | ||
| 0003-flacparse-Avoid-integer-overflow-in-available-data-c.patch | ||
| 0004-qtdemux-Avoid-integer-overflow-when-parsing-Theora-e.patch | ||
| 0005-gdkpixbufdec-Check-if-initializing-the-video-info-ac.patch | ||
| 0006-matroskademux-Only-unmap-GstMapInfo-in-WavPack-heade.patch | ||
| 0007-matroskademux-Fix-off-by-one-when-parsing-multi-chan.patch | ||
| 0008-qtdemux-Fix-integer-overflow-when-allocating-the-sam.patch | ||
| 0009-qtdemux-Make-sure-only-an-even-number-of-bytes-is-pr.patch | ||
| gating.yaml | ||
| gstreamer1-plugins-good-1.16.1-CVE-2026-18296.patch | ||
| gstreamer1-plugins-good-1.16.1-CVE-2026-18298.patch | ||
| gstreamer1-plugins-good-1.16.1-CVE-2026-18299.patch | ||
| gstreamer1-plugins-good-1.16.1-CVE-2026-18649.patch | ||
| gstreamer1-plugins-good-1.16.1-CVE-2026-53705.patch | ||
| gstreamer1-plugins-good-1.16.1-CVE-2026-73433.patch | ||
| gstreamer1-plugins-good-1.16.1-CVE-2026-73434.patch | ||
| gstreamer1-plugins-good-1.16.1-RHEL-246382.patch | ||
| gstreamer1-plugins-good.spec | ||
| sources | ||