I'll check and if possible to update patch.

On Tue, 22 Sept, 2026, 10:19 pm Yoann Congal, <[email protected]> wrote:

> On Wed Sep 16, 2026 at 10:40 AM CEST, Hitendra Prajapati via
> lists.openembedded.org wrote:
> > Pick the patch from [1], also referenced in the Debian report [2] & [3].
> >
> > [1]
> https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/8349cdd35f85246e113b18e55fd11abf9cb248bf
> > [2] https://security-tracker.debian.org/tracker/CVE-2026-3083
> > [3] https://security-tracker.debian.org/tracker/CVE-2026-3085
> >
> > Signed-off-by: Hitendra Prajapati <[email protected]>
> > ---
> >  .../CVE-2026-3083-CVE-2026-3085.patch         | 602 ++++++++++++++++++
> >  .../gstreamer1.0-plugins-good_1.22.12.bb      |   1 +
> >  2 files changed, 603 insertions(+)
> >  create mode 100644
> meta/recipes-multimedia/gstreamer/gstreamer1.0-plugins-good/CVE-2026-3083-CVE-2026-3085.patch
> >
> > diff --git
> a/meta/recipes-multimedia/gstreamer/gstreamer1.0-plugins-good/CVE-2026-3083-CVE-2026-3085.patch
> b/meta/recipes-multimedia/gstreamer/gstreamer1.0-plugins-good/CVE-2026-3083-CVE-2026-3085.patch
> > new file mode 100644
> > index 0000000000..095b511e2f
> > --- /dev/null
> > +++
> b/meta/recipes-multimedia/gstreamer/gstreamer1.0-plugins-good/CVE-2026-3083-CVE-2026-3085.patch
> > @@ -0,0 +1,602 @@
> > +From 8349cdd35f85246e113b18e55fd11abf9cb248bf Mon Sep 17 00:00:00 2001
> > +From: =?UTF-8?q?Tim-Philipp=20M=C3=BCller?= <[email protected]>
> > +Date: Sun, 8 Feb 2026 16:09:04 +0000
> > +Subject: [PATCH] rtpqdm2depay: remove element
> > +
> > +There is no plausible reason anyone should need this element in 2026
> > +seeing that this was a streaming format produced by Darwin Streaming
> Server
> > +ca 2009 which hasn't been in active use for well over a decade.
> > +
> > +It is a maintenance burden and a security liability and there's no
> > +good reason to keep it around.
> > +
> > +Fixes ZDI-CAN-28850, ZDI-CAN-28851, CVE-2026-3083, CVE-2026-3085,
> GST-SA-2026-0008.
> > +
> > +Part-of: <
> https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/10886>
> > +
> > +CVE: CVE-2026-3083 CVE-2026-3085
> > +Upstream-Status: Backport [import from ubuntu
> gst-plugins-good1.0_1.20.3-0ubuntu1.5.debian.tar.xz
> > +Upstream commit
> https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/8349cdd35f85246e113b18e55fd11abf9cb248bf
> ]
> > +Signed-off-by: Hitendra Prajapati <[email protected]>
> > +---
> > + docs/gst_plugins_cache.json |  28 ---
> > + gst/rtp/gstrtp.c            |   1 -
> > + gst/rtp/gstrtpqdmdepay.c    | 411 ------------------------------------
> > + gst/rtp/gstrtpqdmdepay.h    |  83 --------
> > + gst/rtp/meson.build         |   1 -
> > + 5 files changed, 524 deletions(-)
> > + delete mode 100644 gst/rtp/gstrtpqdmdepay.c
> > + delete mode 100644 gst/rtp/gstrtpqdmdepay.h
>
> Hello,
>
> This remove support for a format (this should have been mentionned in
> the commit message!), per stable policy, this is not allowed.
>
> Is there another way to fix these CVEs?
>
> Regards,
> --
> Yoann Congal
> Smile ECS
>
>
-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#246426): 
https://lists.openembedded.org/g/openembedded-core/message/246426
Mute This Topic: https://lists.openembedded.org/mt/121275756/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to