--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-3e109a0c85
2026-10-01 01:11:24.198707+00:00
--------------------------------------------------------------------------------

Name        : ffmpeg
Product     : Fedora 44
Version     : 8.1.3
Release     : 1.fc44
URL         : https://ffmpeg.org/
Summary     : A complete solution to record, convert and stream audio and video
Description :
FFmpeg is a leading multimedia framework, able to decode, encode, transcode,
mux, demux, stream, filter and play pretty much anything that humans and
machines have created. It supports the most obscure ancient formats up to the
cutting edge. No matter if they were designed by some standards committee, the
community or a corporation.


This build of ffmpeg is limited in the number of codecs supported.

--------------------------------------------------------------------------------
Update Information:

Latest upstream bugfix release from 8.1 branch. Changes:
https://code.ffmpeg.org/FFmpeg/FFmpeg/src/branch/release/8.1/Changelog .
--------------------------------------------------------------------------------
ChangeLog:

* Sat Sep 26 2026 Dominik Mierzejewski <[email protected]> - 8.1.3-1
- update to 8.1.3
- drop merged patch
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2494554 - CVE-2026-58049 ffmpeg: FFmpeg: Memory corruption via 
crafted RASC video stream [fedora-43]
        https://bugzilla.redhat.com/show_bug.cgi?id=2494554
  [ 2 ] Bug #2507020 - CVE-2026-64835 ffmpeg: FFmpeg: Arbitrary code execution, 
information disclosure, or denial of service via crafted ADX/AAX audio files 
[fedora-43]
        https://bugzilla.redhat.com/show_bug.cgi?id=2507020
  [ 3 ] Bug #2508218 - CVE-2026-64834 ffmpeg: Denial of Service via crafted 
RTP/ASF stream [fedora-43]
        https://bugzilla.redhat.com/show_bug.cgi?id=2508218
  [ 4 ] Bug #2508449 - CVE-2026-66038 ffmpeg: Information disclosure via 
malformed zlib video stream [fedora-43]
        https://bugzilla.redhat.com/show_bug.cgi?id=2508449
  [ 5 ] Bug #2510587 - CVE-2026-66036 ffmpeg: FFmpeg: Arbitrary code execution 
via crafted video in vf_hqdn3d filter [fedora-43]
        https://bugzilla.redhat.com/show_bug.cgi?id=2510587
  [ 6 ] Bug #2510588 - CVE-2026-66041 ffmpeg: FFmpeg: Arbitrary code execution 
via crafted PGS/SUP subtitle file [fedora-43]
        https://bugzilla.redhat.com/show_bug.cgi?id=2510588
  [ 7 ] Bug #2510589 - CVE-2026-66039 ffmpeg: FFmpeg: Arbitrary code execution 
via crafted CAF file [fedora-43]
        https://bugzilla.redhat.com/show_bug.cgi?id=2510589
  [ 8 ] Bug #2510601 - CVE-2026-66040 ffmpeg: FFmpeg: Arbitrary code execution 
via crafted PNG image [fedora-43]
        https://bugzilla.redhat.com/show_bug.cgi?id=2510601
  [ 9 ] Bug #2511358 - CVE-2026-66037 ffmpeg: FFmpeg: Denial of Service via 
uncontrolled resource consumption in IAMF demuxer [fedora-43]
        https://bugzilla.redhat.com/show_bug.cgi?id=2511358
  [ 10 ] Bug #2516040 - CVE-2026-70631 ffmpeg: FFmpeg: Information disclosure 
via uninitialized heap memory read in TIFF decoder [fedora-43]
        https://bugzilla.redhat.com/show_bug.cgi?id=2516040
  [ 11 ] Bug #2516073 - CVE-2026-70630 ffmpeg: FFmpeg: Information disclosure 
via uninitialized heap memory read in Screenpresso decoder [fedora-43]
        https://bugzilla.redhat.com/show_bug.cgi?id=2516073
  [ 12 ] Bug #2516126 - CVE-2026-70629 ffmpeg: FFmpeg: Information disclosure 
via uninitialized heap memory read in RSCC decoder [fedora-43]
        https://bugzilla.redhat.com/show_bug.cgi?id=2516126
  [ 13 ] Bug #2519501 - CVE-2026-64830 ffmpeg: FFmpeg: Arbitrary code execution 
via heap buffer overflow in VobSub subtitle demuxer. [fedora-43]
        https://bugzilla.redhat.com/show_bug.cgi?id=2519501
  [ 14 ] Bug #2519576 - CVE-2026-70632 ffmpeg: FFmpeg: Arbitrary Code Execution 
in CFHD Decoder via Crafted AVI File [fedora-43]
        https://bugzilla.redhat.com/show_bug.cgi?id=2519576
  [ 15 ] Bug #2519643 - CVE-2026-70628 ffmpeg: FFmpeg: Arbitrary code execution 
via crafted WTV file in DVB subtitle parser [fedora-43]
        https://bugzilla.redhat.com/show_bug.cgi?id=2519643
  [ 16 ] Bug #2519667 - CVE-2026-64832 ffmpeg: FFmpeg: Arbitrary code execution 
via crafted video file in NVDEC hardware decoder [fedora-43]
        https://bugzilla.redhat.com/show_bug.cgi?id=2519667
  [ 17 ] Bug #2525514 - CVE-2026-75147 ffmpeg: FFmpeg: Information disclosure 
or denial of service via crafted AV1 RTP packet [fedora-44]
        https://bugzilla.redhat.com/show_bug.cgi?id=2525514
  [ 18 ] Bug #2525517 - CVE-2026-75146 ffmpeg: FFmpeg: Information disclosure 
and denial of service via out-of-bounds read in DASH demuxer [fedora-43]
        https://bugzilla.redhat.com/show_bug.cgi?id=2525517
  [ 19 ] Bug #2525518 - CVE-2026-75144 ffmpeg: FFmpeg: Memory corruption via 
crafted Dirac data unit [fedora-43]
        https://bugzilla.redhat.com/show_bug.cgi?id=2525518
  [ 20 ] Bug #2525521 - CVE-2026-75142 ffmpeg: FFmpeg: Stack Buffer Overflow in 
MPEG-PS Muxer [fedora-43]
        https://bugzilla.redhat.com/show_bug.cgi?id=2525521
  [ 21 ] Bug #2525523 - CVE-2026-75145 ffmpeg: FFmpeg: Out-of-bounds memory 
access due to integer narrowing conversion [fedora-44]
        https://bugzilla.redhat.com/show_bug.cgi?id=2525523
  [ 22 ] Bug #2526159 - CVE-2026-75143 ffmpeg: FFmpeg Heap Buffer Overflow via 
RIST Protocol Reader [fedora-43]
        https://bugzilla.redhat.com/show_bug.cgi?id=2526159
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-3e109a0c85' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------

-- 
_______________________________________________
package-announce mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/[email protected]
Do not reply to spam, report it: 
https://forge.fedoraproject.org/infra/tickets/issues/new

Reply via email to