Skip to content
SUSE and openSUSE gstreamer-plugins-bad Parser Crash Vulnerability

SUSE and openSUSE gstreamer-plugins-bad Parser Crash Vulnerability

First seen 8 Aug 2026, 17:35 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster August 9, 2026 at 15:34 UTC
  • CVE-2026-52718 affects gstreamer-plugins-bad in SUSE and openSUSE systems.
  • The vulnerability can cause application crashes due to parser desynchronization.
  • Patches are available and should be applied promptly to affected systems.

A moderate vulnerability identified as CVE-2026-52718 affects the gstreamer-plugins-bad package in SUSE and openSUSE systems. This issue arises from a byte count miscalculation in the gst_av1_parser_parse_tile_list_obu() function, leading to parser desynchronization and potential application crashes. The vulnerability has a CVSS score of 6.5, indicating a moderate threat level. Users are advised to apply patches using SUSE's recommended methods, including YaST online_update or 'zypper patch'. The affected systems include SUSE Linux Enterprise Desktop 15 SP7, SUSE Linux Enterprise Server 15 SP7, and openSUSE Leap 15.6. The vulnerability was published on June 15, 2026, and the patch was released on August 7, 2026. Immediate action is recommended to mitigate risks associated with this vulnerability.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 44d ago How this analysis works

Timeline

2026-06-15
CVE-2026-52718 published
The vulnerability affecting gstreamer-plugins-bad was officially disclosed, detailing the byte count issue.
Linuxsecurity
2026-08-07
Patch released for gstreamer-plugins-bad
SUSE released an update to address CVE-2026-52718, urging users to apply the patch immediately.
Linuxsecurity
2026-08-08
Advisories published for affected systems
Both SUSE and openSUSE issued advisories detailing the vulnerability and patch instructions.
Linuxsecurity

More articles in this cluster (4)

Following this threat?

Track CVE-2026-52718 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed