{"schema_version":"1.7.5","id":"MGASA-2026-0222","published":"2026-06-18T18:04:49Z","modified":"2026-06-18T18:34:11.397570106Z","upstream":["CVE-2026-1940","CVE-2026-2920","CVE-2026-2921","CVE-2026-2922","CVE-2026-2923","CVE-2026-3082","CVE-2026-3083","CVE-2026-3085"],"summary":"Updated gstreamer1.0-plugins-bad, gstreamer1.0-plugins-base, gstreamer1.0-plugins-good & gstreamer1.0-plugins-ugly packages fix security vulnerabilities","details":"CVE-2026-2921, GStreamer RIFF Palette Integer Overflow Remote Code\nExecution Vulnerability\nCVE-2026-2923.GStreamer DVB Subtitles Out-Of-Bounds Write Remote Code\nExecution Vulnerability\nCVE-2026-3082, GStreamer JPEG Parser Heap-based Buffer Overflow Remote\nCode Execution Vulnerability\nCVE-2026-3085, GStreamer rtpqdm2depay Heap-based Buffer Overflow Remote\nCode Execution Vulnerability\nCVE-2026-2920, GStreamer ASF Demuxer Heap-based Buffer Overflow Remote\nCode Execution Vulnerability\nCVE-2026-2922, GStreamer ASF Demuxer Heap-based Buffer Overflow Remote\nCode Execution Vulnerability\nCVE-2026-1940, Gstreamer: incomplete fix of CVE-2026-1940\n","affected":[{"package":{"name":"gstreamer1.0-plugins-bad","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/gstreamer1.0-plugins-bad?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.22.11-1.2.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0222.json"}},{"package":{"name":"gstreamer1.0-plugins-base","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/gstreamer1.0-plugins-base?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.22.11-1.3.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0222.json"}},{"package":{"name":"gstreamer1.0-plugins-good","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/gstreamer1.0-plugins-good?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.22.11-1.2.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0222.json"}},{"package":{"name":"gstreamer1.0-plugins-ugly","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/gstreamer1.0-plugins-ugly?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.22.11-1.1.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0222.json"}},{"package":{"name":"gstreamer1.0-plugins-bad","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/gstreamer1.0-plugins-bad?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.22.11-1.2.mga9.tainted"}]}],"ecosystem_specific":{"section":"tainted"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0222.json"}},{"package":{"name":"gstreamer1.0-plugins-ugly","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/gstreamer1.0-plugins-ugly?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.22.11-1.1.mga9.tainted"}]}],"ecosystem_specific":{"section":"tainted"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0222.json"}}],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2026-0222.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=35216"},{"type":"WEB","url":"https://lists.debian.org/debian-security-announce/2026/msg00076.html"},{"type":"WEB","url":"https://lists.debian.org/debian-security-announce/2026/msg00100.html"}],"credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}