已合并
fix CVE-2026-14935 #111
zhangwenyi0929创建于 7月29日
fix CVE-2026-14935 #111
已合并
zhangwenyi0929创建于 7月29日
从已删除 :openEuler-24.03-LTS-SP3合入到src-openeuler/gstreamer1-plugins-bad-freeopenEuler-24.03-LTS-SP3
共 2 个文件变更+40-2
@@ -0,0 +1,31 @@
1+From da08b8584fb0edbc1d5183900729b683c7dd85be Mon Sep 17 00:00:00 2001
2+From: =?UTF-8?q?Sebastian=20Dr=C3=B6ge?= <sebastian@centricular.com>
3+Date: Thu, 25 Jun 2026 11:18:53 +0300
4+Subject: [PATCH] webrtcsdp: Fix inverted fingerprint existence logic
5+ 
6+Fix provided by Clouditera Security, who also reported this.
7+ 
8+Fixes https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5171
9+ 
10+Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12075>
11+---
12+ ext/webrtc/webrtcsdp.c | 4 ++--
13+ 1 file changed, 2 insertions(+), 2 deletions(-)
14+ 
15+diff --git a/ext/webrtc/webrtcsdp.c b/ext/webrtc/webrtcsdp.c
16+index 715391b..b08cfd2 100644
17+--- a/ext/webrtc/webrtcsdp.c
18++++ b/ext/webrtc/webrtcsdp.c
19+@@ -120,8 +120,8 @@ _check_sdp_crypto (SDPSource source, GstWebRTCSessionDescription * sdp,
20+ const gchar *media_fingerprint =
21+ gst_sdp_media_get_attribute_val (media, "fingerprint");
22+
23+- if (!IS_EMPTY_SDP_ATTRIBUTE (message_fingerprint)
24+- && !IS_EMPTY_SDP_ATTRIBUTE (media_fingerprint)) {
25++ if (IS_EMPTY_SDP_ATTRIBUTE (message_fingerprint)
26++ && IS_EMPTY_SDP_ATTRIBUTE (media_fingerprint)) {
27+ g_set_error (error, GST_WEBRTC_BIN_ERROR,
28+ GST_WEBRTC_BIN_ERROR_FINGERPRINT,
29+ "No fingerprint lines in sdp for media %u", i);
30+--
31+2.43.0
@@ -3,7 +3,7 @@
3 3 
4Name: gstreamer1-plugins-bad-free4Name: gstreamer1-plugins-bad-free
5Version: 1.16.25Version: 1.16.2
6-Release: 166+Release: 17
7Summary: Not well tested plugins for GStreamer framework7Summary: Not well tested plugins for GStreamer framework
8License: LGPLv2+ and LGPLv28License: LGPLv2+ and LGPLv2
9URL: http://gstreamer.freedesktop.org/9URL: http://gstreamer.freedesktop.org/
@@ -32,6 +32,7 @@ Patch0013: CVE-2026-2923.patch
32# GStreamer-SA-2026-0043 / CVE-2026-5272032# GStreamer-SA-2026-0043 / CVE-2026-52720
33# https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/f3b66928a194b32b27fac3c3379d3d20e596644233# https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/f3b66928a194b32b27fac3c3379d3d20e5966442
34Patch0014: CVE-2026-52720.patch34Patch0014: CVE-2026-52720.patch
35+Patch0015: CVE-2026-14935.patch
35 36 
36BuildRequires: gstreamer1-devel >= %{version} autoconf37BuildRequires: gstreamer1-devel >= %{version} autoconf
37BuildRequires: gstreamer1-plugins-base-devel >= %{version}38BuildRequires: gstreamer1-plugins-base-devel >= %{version}
@@ -283,7 +284,13 @@ EOF
283%{_libdir}/pkgconfig/gstreamer*-%{majorminor}.pc284%{_libdir}/pkgconfig/gstreamer*-%{majorminor}.pc
284%{_includedir}/gstreamer-%{majorminor}/gst/*285%{_includedir}/gstreamer-%{majorminor}/gst/*
285%changelog286%changelog
286-* Sat Jul 11 2026 Liu Hui <2224621664@qq.com> - 1.16.2-16287+* Sat Jul 29 2026 zhangwenyi <zhangwenyi@xfusion.com> - 1.16.2-17
288+- Type:CVE
289+- CVE:CVE-2026-14935
290+- SUG:NA
291+- DESC:fix CVE-2026-14935
292+ 
293+* Wed Jul 11 2026 Liu Hui <2224621664@qq.com> - 1.16.2-16
287- Type:CVE294- Type:CVE
288- CVE:CVE-2026-52720295- CVE:CVE-2026-52720
289- SUG:NA296- SUG:NA