SUSE and openSUSE gstreamer-plugins-bad Parser Crash Vulnerability

SUSE and openSUSE gstreamer-plugins-bad Parser Crash Vulnerability

First seen 8 Aug 2026, 17:35 UTC www.suse.comLinuxsecurity 97% similarity 57.1

Article Content

Browse articles
ThreatCluster

A moderate vulnerability identified as CVE-2026-52718 affects the gstreamer-plugins-bad package in SUSE and openSUSE systems. This issue arises from a byte count miscalculation in the gst_av1_parser_parse_tile_list_obu() function, leading to parser desynchronization and potential application crashes. The vulnerability has a CVSS score of 6.5, indicating a moderate threat level. Users are advised to apply patches using SUSE's recommended methods, including YaST online_update or 'zypper patch'. The affected systems include SUSE Linux Enterprise Desktop 15 SP7, SUSE Linux Enterprise Server 15 SP7, and openSUSE Leap 15.6. The vulnerability was published on June 15, 2026, and the patch was released on August 7, 2026. Immediate action is recommended to mitigate risks associated with this vulnerability.

Key Points: • CVE-2026-52718 affects gstreamer-plugins-bad in SUSE and openSUSE systems. • The vulnerability can cause application crashes due to parser desynchronization. • Patches are available and should be applied promptly to affected systems.

ThreatCluster AI How this analysis works

Timeline

2026-06-15
CVE-2026-52718 published
The vulnerability affecting gstreamer-plugins-bad was officially disclosed, detailing the byte count issue.
Linuxsecurity
2026-08-07
Patch released for gstreamer-plugins-bad
SUSE released an update to address CVE-2026-52718, urging users to apply the patch immediately.
Linuxsecurity
2026-08-08
Advisories published for affected systems
Both SUSE and openSUSE issued advisories detailing the vulnerability and patch instructions.
Linuxsecurity

Community

Browse all →