openSUSE-SU-2026:20710-1

    Dashboard / Vulnerabilities / openSUSE-SU-2026:20710-1

    openSUSE-SU-2026:20710-1

    Published: 9 May 2026Last Modified: 11 May 2026

    Summary: Security update for ffmpeg-4

    Details: This update for ffmpeg-4 fixes the following issues: Changes in ffmpeg-4: - CVE-2025-59728: Fixed out-of-bounds NUL-byte write when calculating the content path in handling of MPEG-DASH manifests (bsc#1251137). - CVE-2025-7700: Fixed a NULL Pointer Dereference in the ALS Decoder (bsc#1246790) - CVE-2024-36618: Fixed a integer overflow in AVI demuxer (bsc#1234020) - CVE-2023-6601: Fixed HLS Unsafe File Extension Bypass (bsc#1220545). - Update to release 4.4.6 * lavc/libx265: unbreak build for X265_BUILD >= 210 * ARM: vp9mc: Load only 12 pixels in the 4 pixel wide horizontal filter * rtmpproto: Avoid rare crashes in the `fail:` codepath in rtmp_open * avcodec/snow: Fix off by 1 error in run_buffer * avcodec/mpegvideo_enc: Check FLV1 resolution limits

    Affected packages

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    openSUSE-SU-2026:20710-1 | CVE-DB