View at Official suse advisory, NVD, CVE.org · CVE detail
Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.
CVE-2026-46470 severity moderate: SUSE including 2 source package names (gstreamer-plugins-good, gstreamer-plugins-good-lang), 8 product×package rows across 5 product lines (SUSE Linux Enterprise Server 12 SP4-LTSS, SUSE Linux Enterprise Server 12 SP5-LTSS, … (5 product lines)): Known Not Affected 8.
An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's qtdemux_audio_caps function does not sufficiently validate atom data before performing division operations, leading to denial of service due to integer division by zero.