View at Official alpine advisory, NVD, CVE.org · CVE detail
Freshness: no update timestamp found; verify against the upstream OS advisory manually.
CVE-2025-47183: 2 source package rows (gst-plugins-good, gstreamer); 18 state rows across 7 repos (3.19-main, 3.20-main, 3.21-main, 3.22-community, 3.22-main, edge-community, edge-main); fixed 2, open 16.
In GStreamer through 1.26.1, the isomp4 plugin's qtdemux_parse_tree function may read past the end of a heap buffer while parsing an MP4 file, leading to information disclosure.