Skip to main content

Security update for gstreamer-rtsp-server, gstreamer-plugins-ugly, gstreamer-plugins-rs, gstreamer-plugins-libav, gstreamer-plugins-good, gstreamer-plugins-base, gstreamer-plugins-bad, gstreamer-docs, gstreamer-devtools, gstreamer

0
Medium
Published: 03/05/2026 (03/05/2026, 18:13:13 UTC)
Source: GCVE Database
Vendor/Project: SUSE Product Security Team
Product: SUSE

Description

This update for gstreamer-rtsp-server, gstreamer-plugins-ugly, gstreamer-plugins-rs, gstreamer-plugins-libav, gstreamer-plugins-good, gstreamer-plugins-base, gstreamer-plugins-bad, gstreamer-docs, gstreamer-devtools, gstreamer fixes the following issues: Changes in gstreamer-rtsp-server: - Update to version 1.26.7: + Fix issues with G_DISABLE_CHECKS & G_DISABLE_ASSERT. + rtsp-server: tests: Switch to fixtures to ensure pool shutdown + rtsp-server: tests: Fix a few memory leaks Changes in gstreamer-plugins-ugly: - Update to version 1.26.7: + No changes, stable version bump only. Changes in gstreamer-plugins-rs: - Update to version 1.26.7+git0.6ab75814: * tracers: Fix inverted append logic when writing log files * threadshare: - examples: standalone: also handle buffer lists - Pad push_list: downgrade Pad flushing log level - sinks: fix / handle query() - backpressure: abort pending items on flush start - udpsink: fix panic recalculating latency from certain executors - audiotestsrc: . support more Audio formats . use AudioInfo . fix latency . act as a pseudo live source by default - runtime task: execute action in downward transition - example cleanups - udpsink: distinguish sync status for latency & report added latency - sink elements: implement `send_event` - dataqueue elements: report min and max latency * rtp: - Add linear audio (L8, L16, L24) RTP payloaders / depayloaders * rtp: basedepay: reuse last PTS, when possible * skia: Update to skia-safe 0.89 * mp4: Update to mp4-atom 0.9 * Update dependencies * webrtc: livekit: Drop connection lock after take() * onvifmetadatapay: copy metadata from source buffer * fallbacksrc: Fix custom source reuse case * add `rust-tls-native-roots` feature to the `reqwest` dep * rtpamrpay2: - Actually forward the frame quality indicator - Set frame quality indicator flag - Add patch to fix reproducibility of package build (boo#1237097) - Update to version 1.26.6+git20.e287e869: * Fix some new clippy 1.90 warnings * colordetect: Don't use deprecated color_name API * deny: Update * quinn: Update to web-transport-quinn 0.8 * skia: Update to skia-safe 0.88 * Update Cargo.lock * Allow windows-sys 0.61 too * intersink: add sync property * meson: Fix .pc files installation and simplify build output handling. This also fixes the .pc file install directory and ensures that the .pc files are only installed when static builds is enabled. - Drop devel subpackage following upstream changes. - Update to version 1.26.6: + aws: Ensure task stopping on paused-to-ready state change + fallbacksrc: - Don't panic during retries if the element was shut down in parallel - Don't restart source if the element is just being shut down - Fix some custom source deadlocks - Fix sources only being restarted once + gtk4: Try importing dmabufs withouth DMA_DRM caps + inter: Give the appsrc/appsink a name that has the parent element as prefix + mp4: Skip tests using x264enc if it does not exist + rtpgccbwe: avoid clamp() panic when min_bitrate > max_bitrate + rtpmp4gdepay2: allow only constantduration with neither constantsize nor sizelength set + rtprecv: fix race condition on first buffer + speechmatics: Specify rustls as an explicit dependency + spotify: update to librespot 0.7 + threadshare: - add a blocking adapter element - always use block_on_or_add_subtask - audiotestsrc: fix setting samples-per-buffer... - blocking_adapter: fix Since marker in docs - fix resources not available when preparing asynchronously - fix ts-inter test one_to_one_up_first - have: have Task log its obj - intersink: return from blocking tasks when stopping - inter: update doc example - runtime/pad: lower log level pushing Buffer to flushing pad - separate blocking & throttling schedulers - update examples - Update to getifaddrs 0.5 - Fix macOS build post getifaddrs 0.5 update - Bump up getiffaddrs to 0.1.5 and revert "udp: avoid getifaddrs in android" - Reapply "udp: avoid getifaddrs in android" + transcriberbin: Fix some deadlocks + Update dependencies + webrtc: Migrate to warp 0.4 and switch to tokio-rustls + webrtc/signalling: Fix setting of host address + ci: add script to check readme against plugins list + Fix various new clippy 1.89 warnings + Don't suggest running cargo cinstall after cargo cbuild + meson: Isolate built plugins from cargo target directory - Update to version 1.26.5+git11.949807a4 (boo#1248053, CVE-2025-55159): + rtprecv: fix race condition on first buffer + threadshare: intersink: return from blocking tasks when stopping + threadshare: inter: store upstream latency in InterContext + threadshare: add a blocking adapter element + transcriberbin: Fix settings/state lock order vi

Affected software

Affected versions
SUSEaarch64gstreamer-1.26.7-160000.1.1.aarch64gstreamer-devel-1.26.7-160000.1.1.aarch64gstreamer-devtools-1.26.7-160000.1.1.aarch64

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
SUSE Product Security Team
Advisory Id
openSUSE-SU-2026:20329-1
Cve Count
1
State
PUBLISHED

Threat ID: 6aab499455bf5e2cf5990f51

Added to database: 09/17/2026, 01:59:48 UTC

Last updated: 09/17/2026, 02:02:26 UTC

Views: 1

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses