DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-2pww-37mg-mp84

Package

gstreamer-doc

Component

gstreamer-doc

Latest update

Not affected

Aliases

Severity

Unknown
Eliminate CVEs with Chainguard hardened images

Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.

Start for free

References

  • https://nvd.nist.gov/vuln/detail/CVE-2026-12892

Updates

Status

Not affected

Justification

Component not present

Impact

CVE-2026-12892 (GStreamer-SA-2026-0047) is an out-of-bounds read in the GStreamer H.264 codec parser (gsth264parser.c, the h264parse element), which is part of the gst-plugins-bad plugin set — not the core GStreamer framework.

This package provides only the core GStreamer framework (libgstreamer-1.0, coreelements, gst-launch/gst-inspect) and does not include the H.264 codec parser. The match is a CPE name collision (cpe:2.3:a:gstreamer:gstreamer), not the presence of the vulnerable code — so the vulnerable code is not present in this artifact.

The affected parser ships in the separate gst-plugins-bad package; consumers of that package should track the upstream fix (GStreamer-SA-2026-0047).

References:

  • https://nvd.nist.gov/vuln/detail/CVE-2026-12892
  • https://gstreamer.freedesktop.org/security/sa-2026-0047.html

Status

Under investigation


The trusted source for open source

Talk to an expert
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsChainguard OS PackagesChainguard ActionsChainguard Agent SkillsIntegrationsPricing
© 2026 Chainguard, Inc. All Rights Reserved.
Chainguard® and the Chainguard logo are registered trademarks of Chainguard, Inc. in the United States and/or other countries.
The other respective trademarks mentioned on this page are owned by the respective companies and use of them does not imply any affiliation or endorsement.