I'll check and if possible to update patch. On Tue, 22 Sept, 2026, 10:19 pm Yoann Congal, <[email protected]> wrote:
> On Wed Sep 16, 2026 at 10:40 AM CEST, Hitendra Prajapati via > lists.openembedded.org wrote: > > Pick the patch from [1], also referenced in the Debian report [2] & [3]. > > > > [1] > https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/8349cdd35f85246e113b18e55fd11abf9cb248bf > > [2] https://security-tracker.debian.org/tracker/CVE-2026-3083 > > [3] https://security-tracker.debian.org/tracker/CVE-2026-3085 > > > > Signed-off-by: Hitendra Prajapati <[email protected]> > > --- > > .../CVE-2026-3083-CVE-2026-3085.patch | 602 ++++++++++++++++++ > > .../gstreamer1.0-plugins-good_1.22.12.bb | 1 + > > 2 files changed, 603 insertions(+) > > create mode 100644 > meta/recipes-multimedia/gstreamer/gstreamer1.0-plugins-good/CVE-2026-3083-CVE-2026-3085.patch > > > > diff --git > a/meta/recipes-multimedia/gstreamer/gstreamer1.0-plugins-good/CVE-2026-3083-CVE-2026-3085.patch > b/meta/recipes-multimedia/gstreamer/gstreamer1.0-plugins-good/CVE-2026-3083-CVE-2026-3085.patch > > new file mode 100644 > > index 0000000000..095b511e2f > > --- /dev/null > > +++ > b/meta/recipes-multimedia/gstreamer/gstreamer1.0-plugins-good/CVE-2026-3083-CVE-2026-3085.patch > > @@ -0,0 +1,602 @@ > > +From 8349cdd35f85246e113b18e55fd11abf9cb248bf Mon Sep 17 00:00:00 2001 > > +From: =?UTF-8?q?Tim-Philipp=20M=C3=BCller?= <[email protected]> > > +Date: Sun, 8 Feb 2026 16:09:04 +0000 > > +Subject: [PATCH] rtpqdm2depay: remove element > > + > > +There is no plausible reason anyone should need this element in 2026 > > +seeing that this was a streaming format produced by Darwin Streaming > Server > > +ca 2009 which hasn't been in active use for well over a decade. > > + > > +It is a maintenance burden and a security liability and there's no > > +good reason to keep it around. > > + > > +Fixes ZDI-CAN-28850, ZDI-CAN-28851, CVE-2026-3083, CVE-2026-3085, > GST-SA-2026-0008. > > + > > +Part-of: < > https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/10886> > > + > > +CVE: CVE-2026-3083 CVE-2026-3085 > > +Upstream-Status: Backport [import from ubuntu > gst-plugins-good1.0_1.20.3-0ubuntu1.5.debian.tar.xz > > +Upstream commit > https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/8349cdd35f85246e113b18e55fd11abf9cb248bf > ] > > +Signed-off-by: Hitendra Prajapati <[email protected]> > > +--- > > + docs/gst_plugins_cache.json | 28 --- > > + gst/rtp/gstrtp.c | 1 - > > + gst/rtp/gstrtpqdmdepay.c | 411 ------------------------------------ > > + gst/rtp/gstrtpqdmdepay.h | 83 -------- > > + gst/rtp/meson.build | 1 - > > + 5 files changed, 524 deletions(-) > > + delete mode 100644 gst/rtp/gstrtpqdmdepay.c > > + delete mode 100644 gst/rtp/gstrtpqdmdepay.h > > Hello, > > This remove support for a format (this should have been mentionned in > the commit message!), per stable policy, this is not allowed. > > Is there another way to fix these CVEs? > > Regards, > -- > Yoann Congal > Smile ECS > >
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#246426): https://lists.openembedded.org/g/openembedded-core/message/246426 Mute This Topic: https://lists.openembedded.org/mt/121275756/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
