openSUSE 16: gstreamer-plugins-bad / gstreamer-plugins-bad-chromaprint / etc (openSUSE-SU-2026:21370-1)

high Nessus Plugin ID 328916

Synopsis

The remote openSUSE host is missing one or more security updates.

Description

The remote openSUSE 16 host has packages installed that are affected by multiple vulnerabilities as referenced in the openSUSE-SU-2026:21370-1 advisory.

This update for gstreamer-plugins-bad fixes the following issues

- CVE-2026-12891: unchecked aspect_ratio_idc value used as an array index in the H.266 parser could cause a global out- of-bounds read (bsc#1268872).
- CVE-2026-12892: 1-byte heap out-of-bounds read in H.264 NAL extension slice parser (bsc#1268971).
- CVE-2026-14935: webrtcbin accepts remote SDP without a=fingerprint due to inverted presence check (bsc#1271051).
- CVE-2026-52720: invalid check of total area instead of individual dimensions could trigger a heap out- of-bounds write (bsc#1268406).
- CVE-2026-52721: crafted PCAP records during IPv4 or TCP header parsing could cause an out-of-bounds read (bsc#1268408).
- CVE-2026-52722: crafted VMnc stream with large cursor dimensions can overflow signed integer (bsc#1268410).
- CVE-2026-53701: multi-slice-in-tile partitions without slice index bounds checks could trigger an out- of-bounds write (bsc#1268172).
- CVE-2026-53702: incorrect loop bound during H.265 SEI message parsing could result in a stack buffer overflow (bsc#1268168).
- CVE-2026-59692: unvalidated peer certificate Subject DN printed during a DTLS handshake could cause a stack buffer overflow (bsc#1271168).

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://bugzilla.suse.com/1268168

https://bugzilla.suse.com/1268172

https://bugzilla.suse.com/1268406

https://bugzilla.suse.com/1268408

https://bugzilla.suse.com/1268410

https://bugzilla.suse.com/1268872

https://bugzilla.suse.com/1268971

https://bugzilla.suse.com/1271051

https://bugzilla.suse.com/1271168

https://www.suse.com/security/cve/CVE-2026-12891

https://www.suse.com/security/cve/CVE-2026-12892

https://www.suse.com/security/cve/CVE-2026-14935

https://www.suse.com/security/cve/CVE-2026-52720

https://www.suse.com/security/cve/CVE-2026-52721

https://www.suse.com/security/cve/CVE-2026-52722

https://www.suse.com/security/cve/CVE-2026-53701

https://www.suse.com/security/cve/CVE-2026-53702

https://www.suse.com/security/cve/CVE-2026-59692

Plugin Details

Severity: High

ID: 328916

File Name: openSUSE-2026-21370-1.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 7/22/2026

Updated: 7/22/2026

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.12

CVSS v2

Risk Factor: Medium

Base Score: 4.7

Temporal Score: 3.5

Vector: CVSS2#AV:L/AC:H/Au:N/C:P/I:N/A:C

CVSS Score Source: CVE-2026-52721

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS Score Source: CVE-2026-52720

Vulnerability Information

CPE: cpe:/o:novell:opensuse:16.0, p-cpe:/a:novell:opensuse:gstreamer-plugins-bad-chromaprint, p-cpe:/a:novell:opensuse:gstreamer-plugins-bad-devel, p-cpe:/a:novell:opensuse:gstreamer-plugins-bad-lang, p-cpe:/a:novell:opensuse:gstreamer-plugins-bad, p-cpe:/a:novell:opensuse:gstreamer-transcoder-devel, p-cpe:/a:novell:opensuse:gstreamer-transcoder, p-cpe:/a:novell:opensuse:libgstadaptivedemux-1_0-0, p-cpe:/a:novell:opensuse:libgstanalytics-1_0-0, p-cpe:/a:novell:opensuse:libgstbadaudio-1_0-0, p-cpe:/a:novell:opensuse:libgstbasecamerabinsrc-1_0-0, p-cpe:/a:novell:opensuse:libgstcodecparsers-1_0-0, p-cpe:/a:novell:opensuse:libgstcodecs-1_0-0, p-cpe:/a:novell:opensuse:libgstcuda-1_0-0, p-cpe:/a:novell:opensuse:libgstdxva-1_0-0, p-cpe:/a:novell:opensuse:libgstinsertbin-1_0-0, p-cpe:/a:novell:opensuse:libgstisoff-1_0-0, p-cpe:/a:novell:opensuse:libgstmpegts-1_0-0, p-cpe:/a:novell:opensuse:libgstmse-1_0-0, p-cpe:/a:novell:opensuse:libgstphotography-1_0-0, p-cpe:/a:novell:opensuse:libgstplay-1_0-0, p-cpe:/a:novell:opensuse:libgstplayer-1_0-0, p-cpe:/a:novell:opensuse:libgstsctp-1_0-0, p-cpe:/a:novell:opensuse:libgsttranscoder-1_0-0, p-cpe:/a:novell:opensuse:libgsturidownloader-1_0-0, p-cpe:/a:novell:opensuse:libgstva-1_0-0, p-cpe:/a:novell:opensuse:libgstvulkan-1_0-0, p-cpe:/a:novell:opensuse:libgstwayland-1_0-0, p-cpe:/a:novell:opensuse:libgstwebrtc-1_0-0, p-cpe:/a:novell:opensuse:libgstwebrtcnice-1_0-0, p-cpe:/a:novell:opensuse:typelib-1_0-cudagst-1_0, p-cpe:/a:novell:opensuse:typelib-1_0-gstanalytics-1_0, p-cpe:/a:novell:opensuse:typelib-1_0-gstbadaudio-1_0, p-cpe:/a:novell:opensuse:typelib-1_0-gstcodecs-1_0, p-cpe:/a:novell:opensuse:typelib-1_0-gstcuda-1_0, p-cpe:/a:novell:opensuse:typelib-1_0-gstdxva-1_0, p-cpe:/a:novell:opensuse:typelib-1_0-gstinsertbin-1_0, p-cpe:/a:novell:opensuse:typelib-1_0-gstmpegts-1_0, p-cpe:/a:novell:opensuse:typelib-1_0-gstmse-1_0, p-cpe:/a:novell:opensuse:typelib-1_0-gstplay-1_0, p-cpe:/a:novell:opensuse:typelib-1_0-gstplayer-1_0, p-cpe:/a:novell:opensuse:typelib-1_0-gsttranscoder-1_0, p-cpe:/a:novell:opensuse:typelib-1_0-gstva-1_0, p-cpe:/a:novell:opensuse:typelib-1_0-gstvulkan-1_0, p-cpe:/a:novell:opensuse:typelib-1_0-gstvulkanwayland-1_0, p-cpe:/a:novell:opensuse:typelib-1_0-gstvulkanxcb-1_0, p-cpe:/a:novell:opensuse:typelib-1_0-gstwebrtc-1_0

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 7/18/2026

Vulnerability Publication Date: 6/11/2026

Reference Information

CVE: CVE-2026-12891, CVE-2026-12892, CVE-2026-14935, CVE-2026-52720, CVE-2026-52721, CVE-2026-52722, CVE-2026-53701, CVE-2026-53702, CVE-2026-59692