Skip to content
SUSE gstreamer-plugins-bad Moderate Parser Crash Vulnerability 2026-3527

SUSE gstreamer-plugins-bad Moderate Parser Crash Vulnerability 2026-3527

Linuxsecurity LinuxSecurity Advisories August 8, 2026

Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges ×

## This update for gstreamer-plugins-bad fixes the following issue: * CVE-2026-52718: byte count instead of a bit count in gst_av1_parser_parse_tile_list_obu() can cause parser desynchronization and an application crash (bsc#1268394). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3527=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3527=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-3527=1 * openSUSE Leap 15.6

## This update for gstreamer-plugins-bad fixes the following issue: * CVE-2026-52718: byte count instead of a bit count in gst_av1_parser_parse_tile_list_obu() can cause parser desynchronization and an application crash (bsc#1268394). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3527=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3527=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-3527=1 * openSUSE Leap 15.6

* CVE-2026-52718 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

* CVE-2026-52718 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

* Basesystem Module 15-SP7

* Desktop Applications Module 15-SP7

* SUSE Linux Enterprise Desktop 15 SP7

* SUSE Linux Enterprise Real Time 15 SP7

* SUSE Linux Enterprise Server 15 SP7

* SUSE Linux Enterprise Server for SAP Applications 15 SP7

* SUSE Package Hub 15 15-SP7

An update that solves one vulnerability can now be installed.

*

*

Announcement ID: SUSE-SU-2026:3527-1 Release Date: 2026-08-07T14:17:46Z Rating: moderate

Get the latest Linux and open source security news straight to your inbox.

Extracted Entities

Platforms (1)