Release date:
2026-09-29 08:48:29 UTC
Description:
- rebase onto Oracle 1.10.4-2.0.5.el7_9
- the vendor fixes in this build: CVE-2024-47540, CVE-2024-47606, CVE-2024-47613.
Oracle labels its qtdemux Theora patch CVE-2024-47607, but that CVE is the
gst_opus_dec_parse_header overflow in gst-plugins-base; the patch carries
upstream f8e398c4, which is CVE-2024-47606 and is what this package needs
- drop 3 of the 4 TuxCare CVE backports, superseded by the vendor's own patches
- CVE-2026-53705: keep the TuxCare fix as a follow-up patch. The vendor's
Patch1007 protects the dec_data allocation but leaves the output-buffer size
computed in 32-bit arithmetic on this branch, because upstream's fix relies
on a gsize refactor 1.10.4 does not have
- restore the 18-byte WAVEFORMATEX offset that the vendor's Patch1003 dropped
while porting to the pre-2.67.4 glib API; without it every A_MS/ACM Matroska
track gets malformed codec_data
- keep BuildRequires: gtk-doc unbounded rather than Oracle's <= 1.25.1, which no
i686 buildroot can satisfy and which would split the generated documentation
between architectures
- require gstreamer1-plugins-base >= 1.10.4-2.0.3, the first of our builds in
which gst_video_info_set_format() returns the gboolean the vendor's Patch1004
tests
Updated packages:
-
gstreamer1-plugins-good-1.10.4-2.0.5.el7_9.tuxcare.els1.i686.rpm
sha:803d6e51989c64f5d25a2d8ca6c5a7c7a7222423236eb9ccb63dcb5c809d788b
-
gstreamer1-plugins-good-1.10.4-2.0.5.el7_9.tuxcare.els1.x86_64.rpm
sha:467af8c3d6c569ceb92d2ed13661d1e9a95e62d9d00e1f3d5bd269ddb0b89a74
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.