SUSE SLES15 Security Update : ffmpeg-4 (SUSE-SU-2026:2444-1)

high Nessus Plugin ID 321754

Synopsis

The remote SUSE host is missing one or more security updates.

Description

The remote SUSE Linux SLES15 / SLES_SAP15 host has packages installed that are affected by multiple vulnerabilities as referenced in the SUSE-SU-2026:2444-1 advisory.

This update for ffmpeg-4 fixes the following issues

Update to version 4.4.7:

- CVE-2023-6601: HLS Unsafe File Extension Bypass (bsc#1220545).
- CVE-2024-35366: FFmpeg n6.1.1 is Integer Overflow. The vulnerability exists in the parse_options function of sbgdec.c within the libavformat module. When parsing certain options, the software does not adequately validate the i (bsc#1234030).
- CVE-2025-1594: stack-based buffer overflow in function ff_aac_search_for_tns of the file libavcodec/aacenc_tns.c of the component AAC Encoder (bsc#1237561).
- CVE-2025-9951: heap-based buffer overflow in jpeg2000dec (bsc#1249393).
- CVE-2025-10256: NULL pointer dereference in Firequalizer filter (bsc#1249431).
- CVE-2025-63757: accumulation of filtered pixel values can lead to an integer overflow (bsc#1255392).
- CVE-2026-30997: Denial of Service via out-of-bounds read (bsc#1262047).
- CVE-2026-40962: inadequate CENC subsample bounds checks can lead to an integer overflow (bsc#1262237).

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://www.suse.com/security/cve/CVE-2024-35368

https://www.suse.com/security/cve/CVE-2024-36618

https://www.suse.com/security/cve/CVE-2025-59728

https://bugzilla.suse.com/1255392

https://www.suse.com/security/cve/CVE-2025-63757

https://bugzilla.suse.com/1220545

https://www.suse.com/security/cve/CVE-2023-6601

https://bugzilla.suse.com/1262237

https://www.suse.com/security/cve/CVE-2026-40962

https://bugzilla.suse.com/1262047

https://www.suse.com/security/cve/CVE-2026-30997

https://bugzilla.suse.com/1234030

https://bugzilla.suse.com/1237561

https://bugzilla.suse.com/1249393

https://bugzilla.suse.com/1249431

https://www.suse.com/security/cve/CVE-2024-35366

https://www.suse.com/security/cve/CVE-2025-10256

https://www.suse.com/security/cve/CVE-2025-1594

https://www.suse.com/security/cve/CVE-2025-9951

https://lists.suse.com/pipermail/sle-updates/2026-June/047421.html

Plugin Details

Severity: High

ID: 321754

File Name: suse_SU-2026-2444-1.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 6/20/2026

Updated: 6/20/2026

Supported Sensors: Continuous Assessment, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 5.9

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2025-1594

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS Score Source: CVE-2026-40962

CVSS v4

Risk Factor: High

Base Score: 8.7

Threat Score: 7.2

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:A/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N

CVSS Score Source: CVE-2025-59728

Vulnerability Information

CPE: p-cpe:/a:novell:suse_linux:libavutil56_70, p-cpe:/a:novell:suse_linux:libswresample3_9, p-cpe:/a:novell:suse_linux:libpostproc55_9, p-cpe:/a:novell:suse_linux:libavcodec58_134, cpe:/o:novell:suse_linux:15, p-cpe:/a:novell:suse_linux:libswscale5_9, p-cpe:/a:novell:suse_linux:libavformat58_76

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 6/18/2026

Vulnerability Publication Date: 8/8/2024

Reference Information

CVE: CVE-2023-6601, CVE-2024-35366, CVE-2024-35368, CVE-2024-36618, CVE-2025-10256, CVE-2025-1594, CVE-2025-59728, CVE-2025-63757, CVE-2025-9951, CVE-2026-30997, CVE-2026-40962

SuSE: SUSE-SU-2026:2444-1