GStreamer plugins with good code and licensing
Backport upstream fix (commit f9567e3e26c9, MR !11242) for CVE-2026-5056 (ZDI-CAN-29392). The patch adds integer overflow and bounds checks to uncompressed video (uncv) handling in qtdemux.c, including upper bounds on cmpd and uncC component counts, validation of num_components range, component_index bounds checking, and a guard against GST_VIDEO_FORMAT_UNKNOWN before using the format. CVE: CVE-2026-5056 Upstream patches: - https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/11242.patch Resolves: RHEL-222332 This commit was backported by Ymir, a Red Hat Enterprise Linux software maintenance AI agent. Assisted-by: Ymir |
||
|---|---|---|
| .gitignore | ||
| 0001-jitterbuffer-Allow-rtp-caps-without-clock-rate.patch | ||
| 0001-rtpqdm2depay-error-out-if-anyone-tries-to-use-this-e.patch | ||
| gating.yaml | ||
| gstreamer1-plugins-good-1.26.7-CVE-2026-5056.patch | ||
| gstreamer1-plugins-good-1.26.7-CVE-2026-18649.patch | ||
| gstreamer1-plugins-good-1.26.7-CVE-2026-53705.patch | ||
| gstreamer1-plugins-good.spec | ||
| gstreamer-good.appdata.xml | ||
| sources | ||