{"id":"openSUSE-SU-2026:20855-1","summary":"Security update for ffmpeg-4","details":"This update for ffmpeg-4 fixes the following issues:\n\nChanges in ffmpeg-4:\n\n- Add check for the return value of av_malloc_array() to avoid potential NULL pointer dereference.  (CVE-2025-10256, bsc#1249431)\n\n- Update to version 4.4.7:\n  * Codecs, filters and other various bugfixes\n  * aacenc_tns: clamp filter direction energy measurement.  (CVE-2025-1594, bsc#1237561)\n  * avcodec/jpeg2000dec: implement cdef remapping during pixel format matching.  (CVE-2025-9951, bsc#1249393)\n","modified":"2026-06-03T18:24:49.396426165Z","published":"2026-06-01T16:03:14Z","related":["CVE-2024-35366","CVE-2024-35368","CVE-2024-36618","CVE-2025-10256","CVE-2025-1594","CVE-2025-59728","CVE-2025-9951"],"upstream":["CVE-2024-35366","CVE-2024-35368","CVE-2024-36618","CVE-2025-10256","CVE-2025-1594","CVE-2025-59728","CVE-2025-9951"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1234030"},{"type":"REPORT","url":"https://bugzilla.suse.com/1237561"},{"type":"REPORT","url":"https://bugzilla.suse.com/1249393"},{"type":"REPORT","url":"https://bugzilla.suse.com/1249431"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-35366"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-35368"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-36618"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-10256"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-1594"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-59728"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-9951"}],"schema_version":"1.7.5"}