{"id":"openSUSE-SU-2026:21258-1","summary":"Security update for ffmpeg-7","details":"This update for ffmpeg-7 fixes the following issue:\n\n- CVE-2026-30997: out-of-bounds read in the `read_global_param()` function allows for a DoS via crafted input\n  (bsc#1262047).\n","modified":"2026-07-09T18:24:31.623376838Z","published":"2026-07-07T16:58:28Z","related":["CVE-2026-30997"],"upstream":["CVE-2026-30997"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262047"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-30997"}],"affected":[{"package":{"name":"ffmpeg-7","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/ffmpeg-7&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.1.4-160000.2.1"}]}],"ecosystem_specific":{"binaries":[{"libavutil59":"7.1.4-160000.2.1","ffmpeg-7-libavfilter-devel":"7.1.4-160000.2.1","libswscale8":"7.1.4-160000.2.1","ffmpeg-7-libpostproc-devel":"7.1.4-160000.2.1","libpostproc58":"7.1.4-160000.2.1","libavdevice61":"7.1.4-160000.2.1","ffmpeg-7-libswresample-devel":"7.1.4-160000.2.1","libavcodec61":"7.1.4-160000.2.1","ffmpeg-7":"7.1.4-160000.2.1","libavfilter10":"7.1.4-160000.2.1","ffmpeg-7-libswscale-devel":"7.1.4-160000.2.1","ffmpeg-7-libavdevice-devel":"7.1.4-160000.2.1","ffmpeg-7-libavcodec-devel":"7.1.4-160000.2.1","libavformat61":"7.1.4-160000.2.1","libswresample5":"7.1.4-160000.2.1","ffmpeg-7-libavformat-devel":"7.1.4-160000.2.1","ffmpeg-7-libavutil-devel":"7.1.4-160000.2.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21258-1.json"}}],"schema_version":"1.7.5"}