suse · CVE-2026-46470

Quick triage

Priority: medium Published: 2026-05-15 23:14:02 UTC Updated: 2026-05-15 23:14:02 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2026-46470 severity moderate: SUSE including 2 source package names (gstreamer-plugins-good, gstreamer-plugins-good-lang), 8 product×package rows across 5 product lines (SUSE Linux Enterprise Server 12 SP4-LTSS, SUSE Linux Enterprise Server 12 SP5-LTSS, … (5 product lines)): Known Not Affected 8.

Description:

An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's qtdemux_audio_caps function does not sufficiently validate atom data before performing division operations, leading to denial of service due to integer division by zero.

cvelogic Threat Intelligence