Package
gstreamer-doc
Component
gstreamer-doc
Latest update
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Justification
Impact
CVE-2026-12892 (GStreamer-SA-2026-0047) is an out-of-bounds read in the GStreamer H.264 codec parser (gsth264parser.c, the h264parse element), which is part of the gst-plugins-bad plugin set — not the core GStreamer framework.
This package provides only the core GStreamer framework (libgstreamer-1.0, coreelements, gst-launch/gst-inspect) and does not include the H.264 codec parser. The match is a CPE name collision (cpe:2.3:a:gstreamer:gstreamer), not the presence of the vulnerable code — so the vulnerable code is not present in this artifact.
The affected parser ships in the separate gst-plugins-bad package; consumers of that package should track the upstream fix (GStreamer-SA-2026-0047).
References:
Status