The GStreamer project reports:
Multiple security issues were identified and fixed in the GStreamer framework.
- GStreamer-SA-2026-0044: Out-of-bounds read in RTP CELT audio depayloader
- GStreamer-SA-2026-0049: Heap buffer overflow in MPEG-4 Video parser
- GStreamer-SA-2026-0050: Heap buffer overflow in MOV/MP4 moov recovery tool
- GStreamer-SA-2026-0051: Out-of-bounds read in RTP SBC depayloader
- GStreamer-SA-2026-0052: Heap buffer overflow in GdkPixbuf image decoder due to dimension changes
- GStreamer-SA-2026-0053: Stack and heap buffer overflow in Opus audio decoder
- GStreamer-SA-2026-0054: Heap buffer overflow in encoding-target loader on malformed UTF-8 input
- GStreamer-SA-2026-0055: Out-of-bounds read in H.266/VVC parser PPS tile slice loop
- GStreamer-SA-2026-0056: Heap-based buffer overflow in H.266 video parser slice header processing
- GStreamer-SA-2026-0057: Out-of-bounds read in RTP JPEG depayloader
- GStreamer-SA-2026-0058: Out-of-bounds read in ASF demuxer packet payload parsing
- GStreamer-SA-2026-0059: Out-of-bounds read in VP9 parser superframe index parsing
- GStreamer-SA-2026-0060: Stack-based out-of-bounds write in closed caption converter
- GStreamer-SA-2026-0061: Possible authentication bypass in WebRTC SDP fingerprint validation
- GStreamer-SA-2026-0062: Stack buffer overflow in DTLS certificate verification
- GStreamer-SA-2026-0063: Heap out-of-bounds write in RFB source when decoding framebuffer updates
- GStreamer-SA-2026-0064: NULL pointer dereference in WAV parser during adtl chunk parsing in streaming mode
- GStreamer-SA-2026-0065: Integer overflow in Matroska LZO1X decompressor