🛡️ openSUSE-SU-2026:20329-1 — gstreamer (CVE-2025-55159)
Description
Security update for gstreamer-rtsp-server, gstreamer-plugins-ugly, gstreamer-plugins-rs, gstreamer-plugins-libav, gstreamer-plugins-good, gstreamer-plugins-base, gstreamer-plugins-bad, gstreamer-docs, gstreamer-devtools, gstreamer
This update for gstreamer-rtsp-server, gstreamer-plugins-ugly, gstreamer-plugins-rs, gstreamer-plugins-libav, gstreamer-plugins-good, gstreamer-plugins-base, gstreamer-plugins-bad, gstreamer-docs, gstreamer-devtools, gstreamer fixes the following issues:
Changes in gstreamer-rtsp-server:
- Update to version 1.26.7:
+ Fix issues with G_DISABLE_CHECKS & G_DISABLE_ASSERT.
+ rtsp-server: tests: Switch to fixtures to ensure pool shutdown
+ rtsp-server: tests: Fix a few memory leaks
Changes in gstreamer-plugins-ugly:
- Update to version 1.26.7:
+ No changes, stable version bump only.
Changes in gstreamer-plugins-rs:
- Update to version 1.26.7+git0.6ab75814:
- tracers: Fix inverted append logic when writing log files
- threadshare:
- examples: standalone: also handle buffer lists
- Pad push_list: downgrade Pad flushing log level
- sinks: fix / handle query()
- backpressure: abort pending items on flush start
- udpsink: fix panic recalculating latency from certain
executors
- audiotestsrc:
. support more Audio formats
. use AudioInfo
. fix latency
. act as a pseudo live source by default
- runtime task: execute action in downward transition
- example cleanups
- udpsink: distinguish sync status for latency & report added
latency
- sink elements: implement
send_event - dataqueue elements: report min and max latency
- rtp:
- Add linear audio (L8, L16, L24) RTP payloaders / depayloaders
- rtp: basedepay: reuse last PTS, when possible
- skia: Update to skia-safe 0.89
- mp4: Update to mp4-atom 0.9
- Update dependencies
- webrtc: livekit: Drop connection lock after take()
- onvifmetadatapay: copy metadata from source buffer
- fallbacksrc: Fix custom source reuse case
- add
rust-tls-native-rootsfeature to thereqwestdep - rtpamrpay2:
- Actually forward the frame quality indicator
- Set frame quality indicator flag
- Add patch to fix reproducibility of package build (boo#1237097)
- Update to version 1.26.6+git20.e287e869:
- Fix some new clippy 1.90 warnings
- colordetect: Don't use deprecated color_name API
- deny: Update
- quinn: Update to web-transport-quinn 0.8
- skia: Update to skia-safe 0.88
- Update Cargo.lock
- Allow windows-sys 0.61 too
- intersink: add sync property
- meson: Fix .pc files installation and simplify build output
handling. This also fixes the .pc file install directory and
ensures that the .pc files are only installed when static
builds is enabled.
- Drop devel subpackage following upstream changes.
- Update to version 1.26.6:
+ aws: Ensure task stopping on paused-to-ready state change
+ fallbacksrc:
- Don't panic during retries if the element was shut down in
parallel
- Don't restart source if the element is just being shut down
- Fix some custom source deadlocks
- Fix sources only being restarted once
+ gtk4: Try importing dmabufs withouth DMA_DRM caps
+ inter: Give the appsrc/appsink a name that has the parent
element as prefix
+ mp4: Skip tests using x264enc if it does not exist
+ rtpgccbwe: avoid clamp() panic when min_bitrate > max_bitrate
+ rtpmp4gdepay2: allow only constantduration with neither
constantsize nor sizelength set
+ rtprecv: fix race condition on first buffer
+ speechmatics: Specify rustls as an explicit dependency
+ spotify: update to librespot 0.7
+ threadshare:
- add a blocking adapter element
- always use block_on_or_add_subtask
- audiotestsrc: fix setting samples-per-buffer...
- blocking_adapter: fix Since marker in docs
- fix resources not available when preparing asynchronously
- fix ts-inter test one_to_one_up_first
- have: have Task log its obj
- intersink: return from blocking tasks when stopping
- inter: update doc example
- runtime/pad: lower log level pushing Buffer to flushing pad
- separate blocking & throttling schedulers
- update examples
- Update to getifaddrs 0.5
- Fix macOS build post getifaddrs 0.5 update
- Bump up getiffaddrs to 0.1.5 and revert "udp: avoid
getifaddrs in android"
- Reapply "udp: avoid getifaddrs in android"
+ transcriberbin: Fix some deadlocks
+ Update dependencies
+ webrtc: Migrate to warp 0.4 and switch to tokio-rustls
+ webrtc/signalling: Fix setting of host address
+ ci: add script to check readme against plugins list
+ Fix various new clippy 1.89 warnings
+ Don't suggest running cargo cinstall after cargo cbuild
+ meson: Isolate built plugins from cargo target directory
- Update to version 1.26.5+git11.949807a4 (boo#1248053,
CVE-2025-55159):
+ rtprecv: fix race condition on first buffer
+
Affected software
openSUSE-SU-2026:20329-1 is recorded against 10 packages.
- gstreamer (fixed in 1.26.7-160000.1.1)
- gstreamer-devtools (fixed in 1.26.7-160000.1.1)
- gstreamer-docs (fixed in 1.26.7-160000.1.1)
- gstreamer-plugins-bad (fixed in 1.26.7-160000.1.1)
- gstreamer-plugins-base (fixed in 1.26.7-160000.1.1)
- gstreamer-plugins-good (fixed in 1.26.7-160000.1.1)
- gstreamer-plugins-libav (fixed in 1.26.7-160000.1.1)
- gstreamer-plugins-rs (fixed in 1.26.7+git0.6ab75814-160000.1.1)
- gstreamer-plugins-ugly (fixed in 1.26.7-160000.1.1)
- gstreamer-rtsp-server (fixed in 1.26.7-160000.1.1)
Timeline and source
Published on 5 March 2026 and last revised on 23 March 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
www.suse.com (Web)
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| gstreamer | — | 1.26.7-160000.1.1 |
| gstreamer-devtools | — | 1.26.7-160000.1.1 |
| gstreamer-docs | — | 1.26.7-160000.1.1 |
| gstreamer-plugins-bad | — | 1.26.7-160000.1.1 |
| gstreamer-plugins-base | — | 1.26.7-160000.1.1 |
| gstreamer-plugins-good | — | 1.26.7-160000.1.1 |
| gstreamer-plugins-libav | — | 1.26.7-160000.1.1 |
| gstreamer-plugins-rs | — | 1.26.7+git0.6ab75814-160000.1.1 |
| gstreamer-plugins-ugly | — | 1.26.7-160000.1.1 |
| gstreamer-rtsp-server | — | 1.26.7-160000.1.1 |
References
Similar Threats
- Unknown CGA-xcv9-pv5w-j437
- Unknown CGA-r2rm-cvh9-2gxh
- High CVE-2023-37327
- High CVE-2023-37328
- High CVE-2023-37329
Free Vulnerability Check
Is your site affected by openSUSE-SU-2026:20329-1?
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against openSUSE-SU-2026:20329-1 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.