=== release 1.28.8 ===

2026-10-08 17:20:32 +0200  Tim-Philipp Müller <tim@centricular.com>

	* gst-plugins-bad.doap:
	* meson.build:
	  Release 1.28.8

2026-06-19 09:43:52 -0400  Xavier Claessens <xclaessens@netflix.com>

	* gst-libs/gst/webrtc/nice/nice.c:
	  webrtc: nice: Fix crash when failing to get local credentials
	  `nice_agent_get_local_credentials()` can return TRUE while leaving
	  `ufrag` and `password` uninitialised. See:
	  https://gitlab.freedesktop.org/libnice/libnice/-/merge_requests/351
	  Even when it returns FALSE, there is no guarantee that `ufrag` and
	  `password` have been set to NULL. Initialize them to NULL to avoid using
	  uninitialized memory.
	  Fixes: #5138
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12454>

2026-09-22 16:56:55 +0200  Víctor Manuel Jáquez Leal <vjaquez@igalia.com>

	* tests/examples/vulkan/vulkanenc.c:
	  example: vulkanenc: fix string deallocation
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12573>

2026-09-15 16:57:31 +0200  Víctor Manuel Jáquez Leal <vjaquez@igalia.com>

	* tests/check/libs/vkvideoencodeav1.c:
	  tests: vulkan: free parser only if it's instantiated
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12573>

2026-09-22 18:04:56 +0200  Víctor Manuel Jáquez Leal <vjaquez@igalia.com>

	* ext/vulkan/vkh265dec.c:
	  vulkanh265dec: fix the level conversion
	  Because the numbers weren't correct. Regardless, in NVIDIA, fluster's number
	  remains the same.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12575>

2026-09-22 18:05:16 +0200  Víctor Manuel Jáquez Leal <vjaquez@igalia.com>

	* ext/vulkan/vkh264dec.c:
	  vulkanh264dec: use level symbols rather numbers
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12575>

2026-09-24 14:43:03 +0200  Víctor Manuel Jáquez Leal <vjaquez@igalia.com>

	* gst-libs/gst/vulkan/gstvkencoder-private.c:
	  vulkan: encoder: synchronize reference pictures before encoding
	  Add explicit dependency and frame barriers for each referenced DPB buffer, for
	  non-layered DPB buffer encoders.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12570>

2026-09-10 18:01:43 +0200  Víctor Manuel Jáquez Leal <vjaquez@igalia.com>

	* gst-libs/gst/vulkan/gstvkencoder-private.c:
	  vulkan: encoder: release DPB slot 0 when clearing a picture
	  The encode path assigns slot indices starting at 0, but
	  gst_vulkan_encoder_picture_clear() only released slots whose index was > 0, so
	  any DBP picture bound to slot 0 is leaked.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12570>

2026-10-08 12:50:00 +0900  Seungha Yang <seungha@centricular.com>

	* gst-libs/gst/hip/gsthipevent.cpp:
	  hipevent: Fix device ID getter
	  Return device ID instead of vendor ID
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12669>

2026-09-23 21:17:02 +0300  Sebastian Dröge <sebastian@centricular.com>

	* gst/closedcaption/gstcccombiner.c:
	  closedcaption: Use truncated length when converting CEA608 S334-1A data too
	  Fixes https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5309
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12661>

2026-09-23 19:22:19 +0300  Sebastian Dröge <sebastian@centricular.com>

	* gst/closedcaption/ccutils.c:
	  closedcaption: Use truncated length when converting CEA708 data too
	  Fixes https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5264
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12661>

2026-10-01 16:04:49 -0700  Finlay Moss <fin@cofibrant.ai>

	* ext/rsvg/gstrsvgdec.c:
	  rsvgdec: Fix out-of-bounds read when scanning for SVG end tag
	  gst_rsvg_dec_parse() scans backwards for an end tag starting at
	  i = size - 6. That leaves room for the 6-byte "</svg>" comparison, but
	  the subsequent comparison against the 10-byte "</svg:svg>" literal reads
	  10 bytes from data + i, which runs up to 4 bytes past the end of the
	  mapped adapter buffer for the first iterations (i > size - 10).
	  Guard the 10-byte memcmp with an explicit bounds check so it only runs
	  when at least 10 bytes are available from the current offset.
	  Found with ASan via the gst-discoverer fuzz target; reproducible with a
	  41-byte SVG (e.g. '<svg xmlns="http://www.w3.org/2000/svg"/>').
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12660>

2026-10-07 11:43:10 +0900  Seungha Yang <seungha@centricular.com>

	* gst-libs/gst/hip/gsthipmemory.cpp:
	  hipmemory: Fix typo in doc
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12636>

2026-10-07 12:05:18 +0900  Seungha Yang <seungha@centricular.com>

	* gst-libs/gst/hip/gsthipmemory.cpp:
	  hipmemory: Fix possible leak in GstAllocator::mem_copy
	  Add missing unref in error path
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12636>

2026-10-03 16:07:31 +0900  Seungha Yang <seungha@centricular.com>

	* sys/nvcodec/gstnvh264dec.cpp:
	  nvh264dec: Fix top field POC in DPB entry
	  Fix copy/paste typo. Use top_field_order_cnt when filling
	  the top field POC from the complementary field.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12608>

2022-04-13 13:42:14 +0000  Abdulla Anam <abduanam@amazon.com>

	* gst-libs/gst/mpegts/gst-atsc-section.c:
	  mpegts: fix GError usage in a loop
	  After the first error occurred, the variable wasn't re-initialized to
	  NULL for subsequent iterations.
	  Also narrow the scope of the err variable.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12605>

2026-10-01 10:40:32 -0600  Jeremy Whiting <jeremy.whiting@collabora.com>

	* ext/analyticsoverlay/gstobjectdetectionoverlay.c:
	* ext/analyticsoverlay/gstsegmentationoverlay.c:
	  analyticsoverlay: Clear pointers in stop to not leak
	  A CI valgrind test saw object detection overlay isn't properly
	  clearing the composition pointer.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12595>

2026-09-29 07:44:04 -0600  Jeremy Whiting <jeremy.whiting@collabora.com>

	* ext/analyticsoverlay/gstsegmentationoverlay.c:
	* tests/check/elements/segmentationoverlay.c:
	* tests/check/meson.build:
	  segmentationoverlay: Fix off-by-one bug and add test
	  Every canvas row was drawn from the mask row meant
	  for the row below, and the last row was never written,
	  so it showed uninitialized memory.
	  The row pointers are now set before each row is drawn instead
	  of after.
	  It was introduced in
	  2ce06a7736 "segmentationoverlay: Respect video meta strides".
	  Also adds a test to check that it doesn't regress later.
	  This bug also is on 1.28 so should be cherry-picked there.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12595>

2026-09-24 01:28:35 +1000  Jan Schmidt <jan@centricular.com>

	* ext/analyticsoverlay/gstsegmentationoverlay.c:
	  segmentationoverlay: Respect video meta strides
	  Don't assume tightly packed data when reading or generating
	  video buffers. We have video meta, and can use the correct
	  stride
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12566>

2026-05-20 13:12:15 -0400  Nicolas Dufresne <nicolas.dufresne@collabora.com>

	* sys/va/gstvafilter.c:
	  va: compositor: Fix alpha blending with Intel driver
	  On Intel driver, the driver will only perform a blend rather then a copy if the
	  blend state pointer is not null. Pass a pointer to a zero-initialized blend
	  state in order to enable alpha blending by default.
	  Fixes #5114
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12557>

2026-09-25 18:49:16 +0100  Tim-Philipp Müller <tim@centricular.com>

	* ext/vmaf/gstvmafelement.c:
	  vmaf: use GST_PARAM_DOC_SHOW_DEFAULT for "threads" property
	  .. so that when the docs get regenerated it doesn't just put in
	  the number of cores of whatever the CI runner happens to have at
	  the time.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12556>

2026-09-25 18:47:29 +0100  Tim-Philipp Müller <tim@centricular.com>

	* ext/vmaf/gstvmafelement.c:
	  vmaf: use G_PARAM_STATIC_STRINGS for property registrations
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12556>

2026-03-25 13:21:57 +0000  Tim-Philipp Müller <tim@centricular.com>

	* docs/plugins/gst_plugins_cache.json:
	* ext/vmaf/gstvmafelement.c:
	  vmaf: change "threads" property default to 0 for automatic
	  .. determination of number of machine CPUs.
	  Fixes hard-coding the CPU value of the CI runner in the docs.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12556>

2026-09-24 12:08:36 +0300  Vivia Nikolaidou <vivia@ahiru.eu>

	* gst/closedcaption/ccutils.c:
	  ccutils: Fix dead code
	  cc_type was the result of a "& 0x03" operation and then was checked against "&
	  0x10", resulting in the check result being dead code, and as a result, a valid
	  cea608 triplet appearing after a valid cea708 triplet was not discarded as it
	  should.
	  The correct value to compare against is 0x02, so the bug was likely the result
	  of binary vs hex confusion.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12543>

2026-09-24 12:04:38 +0300  Vivia Nikolaidou <vivia@ahiru.eu>

	* gst/closedcaption/ccutils.c:
	  ccutils: Fix loop pair parsing indexing
	  The loop was parsing pairs of data but advancing one item at a time, resulting
	  in {1, 2, 3, 4} being parsed as {1, 2} and then {2, 3}, resulting in some items
	  being duplicated and other items being dropped.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12543>

2026-09-23 10:20:00 +0300  Sebastian Dröge <sebastian@centricular.com>

	* ext/avtp/gstavtpcvfdepay.c:
	  avtpcvfdepay: Check that enough data is available for reading the H.264 NAL type
	  Validated packets are always passed to gst_avtp_cvf_depay_get_nal_type()
	  afterwards, which is reading the first byte to get the NAL type.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12533>

2026-09-23 10:23:11 +0300  Sebastian Dröge <sebastian@centricular.com>

	* ext/avtp/gstavtprvfdepay.c:
	  avtprvfdepay: Check that enough data is available for the timestamp and a non-zero fragment size
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12533>

2026-09-23 09:49:57 +0300  Sebastian Dröge <sebastian@centricular.com>

	* gst/gdp/dataprotocol.c:
	  gdp: Check for enough available data before parsing GDP 0.2 seek event
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12533>

2026-09-22 19:18:34 +0100  Tim-Philipp Müller <tim@centricular.com>

	* gst/jpegformat/gstjpegparse.c:
	  jpegparse: handle missing NUL terminator in COM segment
	  Best not to assume that there is a NUL terminator in the segment data.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12526>

2026-09-20 02:01:30 +0200  Maksim Nikolaev <maksim.nikolaev.dev@gmail.com>

	* sys/amfcodec/gstamfav1enc.cpp:
	  amfav1enc: Force a key frame on force-key-unit
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12524>

2026-09-21 10:54:22 +0000  Bruno Fournier <xxtqqtx@gmail.com>

	* gst/adpcmenc/adpcmenc.c:
	  adpcmenc: reject block sizes that are not a multiple of the chunk size
	  The IMA encode loop processes 8 samples (4 bytes) per channel per iteration,
	  so the block must hold the per-channel header plus a whole number of those
	  chunks. A block size where (block_size - 4 * channels) is not a multiple of
	  4 * channels would leave a partial, uninitialized chunk in the output and
	  does not correspond to any real ADPCM stream. Reject such configurations in
	  _setup instead of producing a malformed block.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12515>

2026-09-20 18:50:51 +0000  Bruno Fournier <xxtqqtx@gmail.com>

	* gst/adpcmenc/adpcmenc.c:
	  adpcmenc: stop the IMA encode loop before reading past the input frame
	  The while (write_pos < blocksize) loop advances output in fixed
	  4 * channels-byte steps and input in CHANNEL_CHUNK_SIZE * channels-sample
	  steps. When blocksize - HEADER_SIZE * channels is not a multiple of
	  4 * channels, the final iteration reads beyond the samples_per_block *
	  channels samples the base class guarantees, causing an out-of-bounds read
	  on the input frame (the case the existing "Ran past the end." log flagged).
	  Bound the loop so it never reads past the available input. The default
	  blockalign=1024 path is already aligned and is unchanged.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12515>

2026-09-14 15:36:03 +0200  Piotr Brzeziński <piotr@centricular.com>

	* gst/mxf/mxfmux.c:
	  mxfmux: Fix possible crash when adding a new segment due to frame reordering
	  A simple pipeline such as videotestsrc ! x264enc ! queue ! mxfmux !
	  fakesink can easily segfault if mxfmux has to add a 'future' segment due
	  to frame reordering, and the g_array_append_val() call happens to move
	  the array elsewhere in memory, invalidating our segment pointer.
	  The fix is simply one more g_array_index() call to get a fresh pointer,
	  same as it's already done above after the 'normal' segment addition
	  block.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12506>

2026-09-14 10:59:39 +0900  Seungha Yang <seungha@centricular.com>

	* sys/d3d12/gstd3d12convert.cpp:
	  d3d12convert: Fix caps transformation with overlay features
	  Check for D3D12 memory using contains instead of exact feature
	  equality when transforming caps
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12480>

2026-09-13 14:08:48 +0900  Seungha Yang <seungha@centricular.com>

	* sys/d3d12/gstd3d12convert.cpp:
	  d3d12convert: Handle meta transform
	  Transform metas depending on geometry changes, instead of
	  letting it be silently dropped by basetransform
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12480>

2026-09-13 14:31:04 +0900  Seungha Yang <seungha@centricular.com>

	* sys/d3d12/gstd3d12memorycopy.cpp:
	  d3d12upload, d3d12download: Preserve overlay composition meta
	  This behavior wasn't ported when this new upload/download were reimplemented
	  in https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/7119
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12480>

2026-09-13 14:18:09 +0900  Seungha Yang <seungha@centricular.com>

	* sys/d3d12/gstd3d12memorycopy.cpp:
	  d3d12upload, d3d12download: Preserve metas with known video tags
	  Upload and download perform only memory copies without transforms,
	  so metas with known video tags can be preserved
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12480>

2026-09-13 15:11:23 +0900  Seungha Yang <seungha@centricular.com>

	* sys/d3d12/gstd3d12basefilter.cpp:
	  d3d12basefilter: Preserve metas with known video tags
	  Preserve metas with known video tags by default, with subclass
	  filtering out or transforming them as needed
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12480>

2026-05-18 20:48:19 +0300  Sebastian Dröge <sebastian@centricular.com>

	* gst/mxf/mxfaes-bwf.c:
	  mxfdemux: Add support for reading AAF AIFF-AIFC audio
	  This is effectively the same as BWF but with different labels.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12453>

2026-09-07 20:17:18 +0100  Tim-Philipp Müller <tim@centricular.com>

	* meson.build:
	  Back to development after 1.28.7

=== release 1.28.7 ===

2026-09-07 20:11:13 +0100  Tim-Philipp Müller <tim@centricular.com>

	* gst-plugins-bad.doap:
	* meson.build:
	  Release 1.28.7

2026-09-02 17:52:16 +0200  Stéphane Cerveau <scerveau@igalia.com>

	* ext/vulkan/vkav1dec.c:
	* ext/vulkan/vkvp9dec.c:
	  vulkan(av1,vp9)dec: set access NONE at buffer pool allocation parameters
	  Fixing VUID 03915 as the decoding queue might not have transfer
	  capabilities, see anv driver.
	  See #7165
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12417>

2026-09-03 14:28:18 -0400  Thibault Saunier <tsaunier@igalia.com>

	* tests/validate/autovideoconvert/renegotiate.validatetest:
	* tests/validate/codectimestamper/h264_propagate_caps.validatetest:
	* tests/validate/opencv/cvtracker.validatetest:
	* tests/validate/testsrcbin/caps_spec.validatetest:
	* tests/validate/vtenc/vtenc_h264.validatetest:
	* tests/validate/vtenc/vtenc_h264_b_frames.validatetest:
	* tests/validate/vtenc/vtenc_h265.validatetest:
	* tests/validate/vtenc/vtenc_h265_b_frames.validatetest:
	  validate: Reindent all validatetest files
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12343>

2026-03-03 15:02:23 +0000  Thibault Saunier <tsaunier@igalia.com>

	* tests/validate/autovideoconvert/renegotiate.validatetest:
	* tests/validate/codectimestamper/h264_propagate_caps.validatetest:
	* tests/validate/opencv/cvtracker.validatetest:
	* tests/validate/testsrcbin/caps_spec.validatetest:
	* tests/validate/vtenc/vtenc_h264.validatetest:
	* tests/validate/vtenc/vtenc_h264_b_frames.validatetest:
	* tests/validate/vtenc/vtenc_h265.validatetest:
	* tests/validate/vtenc/vtenc_h265_b_frames.validatetest:
	  validateflow: auto-derive directories from test file path
	  Allow validateflow configs to be written as proper nested structures
	  instead of requiring the $(validateflow) variable expansion:
	  configs = {
	  [validateflow, pad=sink:sink, buffers-checksum=true],
	  }
	  instead of:
	  configs = {
	  "$(validateflow), pad=sink:sink, buffers-checksum=true",
	  }
	  When expectations-dir or actual-results-dir are not explicitly set,
	  validate_flow_override_new() now derives them from the __filename__
	  metadata field (already attached to each config structure by the
	  parser). This mirrors the path computation done in
	  gst_validate_structure_set_variables_from_struct_file().
	  The $(validateflow) variable and the old string syntax remain fully
	  supported for backward compatibility.
	  Port all existing .validatetest files to the new syntax.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12343>

2026-08-08 12:12:09 +0200  Mark Nauwelaerts <mnauw@users.sourceforge.net>

	* gst/mpegdemux/gstmpegdemux.c:
	  mpegdemux: restore gap sending
	  Gap logic was ported from tsdemux in commit 1b762ba0129610f742b9855e435bce5444a4d553.
	  However, gap_ref_buffers was never updated, so it remains 0 and would therefore
	  prevent sending gap events on a stream once it sent a single buffer.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12400>

2026-09-01 20:10:33 +0300  Sebastian Dröge <sebastian@centricular.com>

	* gst-libs/gst/hip/gsthipstream.cpp:
	  hipstream: Return actual device_id instead of vendor from device_id getter
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12394>

2026-09-01 14:31:58 +0200  Edward Hervey <edward@centricular.com>

	* gst/pnm/gstpnmutils.c:
	* tests/check/elements/pnm.c:
	  pnmdec: Protect against bogus dimensions headers
	  Fixes https://oss-fuzz.com/testcase-detail/4567215417131008
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12390>

2026-04-16 12:33:55 +0200  Pablo García <pgarcia@fluendo.com>

	* gst/mpegtsdemux/tsdemux.c:
	  tsdemux: Add 'stream-format' field for AC-4 caps
	  According to Annex G of the AC-4 spec, the syncframe is an optional
	  layer for encapsulating AC-4 raw frames. This demuxer always outputs
	  syncframes, but the AC-4 parser/decoder needs to know.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12371>

2026-08-29 21:42:48 +0900  Seungha Yang <seungha@centricular.com>

	* gst-libs/gst/d3d12/gstd3d12converter-unpack.cpp:
	* gst-libs/gst/d3d12/gstd3d12stagingmemory.h:
	  d3d12: Fix copy-paste typos
	  Fix copy-paste typos in unpack code and staging memory header
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12368>

2026-07-04 18:02:56 +0200  Antonio Rojas <arojas@archlinux.org>

	* ext/opencv/gstcameracalibrate.cpp:
	* ext/opencv/gstfaceblur.h:
	* ext/opencv/gstfacedetect.h:
	* ext/opencv/gsthanddetect.h:
	* ext/opencv/gstsegmentation.cpp:
	* gst-libs/gst/opencv/meson.build:
	  opencv: Support OpenCV 5
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12363>

2026-08-28 13:08:08 +0900  Seungha Yang <seungha@centricular.com>

	* sys/hip/gsthipmemorycopy.cpp:
	  hipmemorycopy: Add missing ifdef guard
	  All the code in gst_hip_memory_copy_before_transform() requires
	  GstCuda to be enabled
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12361>

2026-08-23 12:15:51 +0900  Seungha Yang <seungha@centricular.com>

	* gst-libs/gst/d3d12/gstd3d12cmdqueue.cpp:
	  d3d12cmdqueue: Fix deadlock during GC
	  Release completed GC data without lock taken since
	  notify can acquire other locks
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12353>

2026-08-12 14:31:34 +0900  Seungha Yang <seungha@centricular.com>

	* gst/mxf/mxfdemux.c:
	  mxfdemux: Fix keyframe detection
	  According to ST 377-1:2019, 11.2.3, PosTableIndex in
	  Delta Entry Array specifies temporal reordering and is not related
	  to the random access flag in an Index Entry.
	  As it's already done in the keyframe search code above, always
	  respect the 0x80 random access flag when determining whether an
	  index entry is a keyframe
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12324>

2026-08-21 20:26:02 +0900  Seungha Yang <seungha@centricular.com>

	* sys/hip/meson.build:
	  hip: Fix hipcc detection on Windows with HIP SDK 7.x
	  The hipcc compiler binary name was changed at some point between
	  6.x and 7.x. Try to find hipcc.exe too
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12332>

2026-06-02 12:54:33 +0200  Stéphane Cerveau <scerveau@igalia.com>

	* ext/onnx/gstonnxinference.c:
	* gst-libs/gst/analytics/modelinfo.c:
	  onnxinference: fix dead lock with wrong model file
	  If the model file is not reachable, error out on resource error and
	  release the object lock before to avoid dead lock from
	  GST_ELEMENT_ERROR.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12329>

2026-08-17 12:49:02 +0200  Stéphane Cerveau <scerveau@igalia.com>

	* ext/onnx/gstonnxinference.c:
	  onnxinference: drop redundant status cleanup in output loop
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12329>

2026-08-18 12:48:42 +0530  Nirbheek Chauhan <nirbheek@centricular.com>

	* sys/androidmedia/gstamc.c:
	* sys/androidmedia/gstamc.h:
	* sys/androidmedia/gstamcvideodec.c:
	* sys/androidmedia/gstamcvideoenc.c:
	  amc: Don't set the Hardware class in metadata for sw video codecs
	  This is required for decodebin and apps to be able to detect when hw
	  codecs or sw codecs are being used.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12327>

2026-06-14 22:58:02 +0900  masa-iwm <masa.iwm@gmail.com>

	* sys/dwrite/gstdwritebaseoverlay.cpp:
	  dwritebaseoverlay: Fix assertion 'G_VALUE_HOLDS_UINT (value)'
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12323>

2026-08-11 17:03:45 +0900  masa-iwm <37230118+masa-iwm@users.noreply.github.com>

	* sys/d3d12/gstd3d12dxgicapture.cpp:
	  d3d12screencapturesrc: Fix out-of-bounds access with monochrome cursors
	  Fixed an issue where attempting to capture monochrome cursors,
	  such as high-contrast cursors, resulted in an out-of-bounds access.
	  The code for d3d11screencapturesrc was correct,
	  and the access range has now been aligned with it.
	  Fixes: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5259
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12320>

2026-08-10 18:15:14 +0900  Seungha Yang <seungha@centricular.com>

	* gst-libs/gst/hip/meson.build:
	  hip: Add missing API version suffix in library filename
	  Fixes: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5245
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12299>

2026-08-13 10:46:24 +0900  Seungha Yang <seungha@centricular.com>

	* ext/onnx/gstonnxinference.c:
	  onnx: Fix nullptr dereference on ORT init failure
	  Error out if failed to get the OrtApi object
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12295>

2026-08-06 11:46:33 +0300  Sebastian Dröge <sebastian@centricular.com>

	* gst/jpegformat/gstjpegparse.c:
	  jpegparse: Read app0 id in a host-endianness-independent way
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12259>

2026-08-06 10:55:11 +0800  Lei Zhen <leo.zhen@netint.cn>

	* gst/jpegformat/gstjpegparse.c:
	  jpegparse: Fix byte order of JFIF density fields
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12259>

2026-08-03 17:48:41 +0300  Sebastian Dröge <sebastian@centricular.com>

	* gst/tensordecoders/gstssdtensordec.c:
	  ssdtensordec: The classes were off by one
	  The first reported class is class 1, but that's at index 0 in the labels file.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12256>

2026-08-05 13:04:46 +0100  Tim-Philipp Müller <tim@centricular.com>

	* meson.build:
	  Back to development after 1.28.6

=== release 1.28.6 ===

2026-08-05 12:59:39 +0100  Tim-Philipp Müller <tim@centricular.com>

	* gst-plugins-bad.doap:
	* meson.build:
	  Release 1.28.6

2026-07-08 17:05:14 +0300  Sebastian Dröge <sebastian@centricular.com>

	* ext/openjpeg/gstopenjpegdec.c:
	  openjpegdec: Clamp x0/x1/y0/y1 to the available frame size in stripe mode
	  While y0/y1 were already clamped, the lack of clamping x0/x1 allowed caps to
	  specify a different size than the actual frame which could then lead to reading
	  or writing too many bytes.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12246>

2026-07-07 17:20:50 +0300  Sebastian Dröge <sebastian@centricular.com>

	* ext/openjpeg/gstopenjpegdec.c:
	  openjpegdec: Use gsize for strides instead of gint
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12246>

2026-07-07 15:22:34 +0300  Sebastian Dröge <sebastian@centricular.com>

	* ext/openjpeg/gstopenjpeg.h:
	* ext/openjpeg/gstopenjpegdec.c:
	  openjpegdec: Fix some typos in error messages
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12246>

2026-07-07 15:18:10 +0300  Sebastian Dröge <sebastian@centricular.com>

	* ext/openjpeg/gstopenjpegdec.c:
	  openjpegdec: Unmap input/output buffers in error cases
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12246>

2026-07-07 16:28:28 +0300  Sebastian Dröge <sebastian@centricular.com>

	* ext/openjpeg/gstopenjpegdec.c:
	  openjpegdec: Only use YOsiz and Ysiz in striped mode and clamp to caps height
	  We assume that in striped mode the smallest YOsiz of a frame is always 0.
	  Fixes https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5187
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12246>

2026-07-07 15:20:51 +0300  Sebastian Dröge <sebastian@centricular.com>

	* ext/openjpeg/gstopenjpegdec.c:
	  openjpegdec: Negotiate with width/height of the actual image instead of upstream caps
	  In non-striped mode. This allows us to not rely on the upstream caps being
	  correct and work from the data we have anyway.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12246>

2026-08-03 12:30:45 +0300  Sebastian Dröge <sebastian@centricular.com>

	* gst/adpcmdec/adpcmdec.c:
	  adpcmdec: Fix IMA ADPCM input size check to match with the actual code
	  Fixes https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5231
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12245>

2026-08-03 12:30:30 +0300  Sebastian Dröge <sebastian@centricular.com>

	* gst/adpcmdec/adpcmdec.c:
	  adpcmdec: Fail negotiation if block_align is not provided
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12245>

2026-07-13 11:04:28 +0900  Seungha Yang <seungha@centricular.com>

	* gst-libs/gst/codecparsers/gsth265parser.c:
	  h265parser: Fix out-of-bounds writes in RPS parsing
	  Add missing bounds checks.
	  Fixes: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5196
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12239>

2026-07-18 16:19:17 +0200  Tim-Philipp Müller <tim@centricular.com>

	* ext/bz2/gstbz2dec.h:
	* ext/bz2/gstbz2enc.h:
	* ext/dtls/gstdtlsagent.h:
	* ext/dtls/gstdtlscertificate.h:
	* ext/dtls/gstdtlsconnection.h:
	* ext/resindvd/rsndec.h:
	* ext/ttml/gstttmlrender.h:
	* ext/wayland/gstwaylandsink.h:
	* gst/debugutils/gsttestsrcbin.c:
	* gst/pnm/gstpnmdec.h:
	* gst/pnm/gstpnmenc.h:
	* gst/transcode/gst-cpu-throttling-clock.h:
	* sys/kms/gstkmsallocator.h:
	* sys/kms/gstkmsbufferpool.h:
	* sys/kms/gstkmssink.h:
	* sys/va/gstvafilter.h:
	  gst-plugins-bad: remove incorrect G_GNUC_CONST annotation for get_type() functions
	  G_GNUC_CONST must only be used for functions that don't modify global state.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12157>

2026-06-19 10:49:57 +0100  Charles <charles05@canonical.com>

	* ext/dtls/gstdtlsconnection.c:
	  dtls: make BIO read signal retry instead of EOF when no data
	  The DTLS plugin was using OpenSSL through a custom memory BIO registered
	  via BIO_meth_set_read. When the handshake is driven and no incoming datagram is
	  queued, the bio_method_read callback returned 0 without setting the read-retry
	  flag, while the BIO's BIO_CTRL_EOF control reports "not at EOF". This is invalid
	  usage, a BIO that has no data available right now must signal retry, not return
	  0.
	  Up to and including OpenSSL 3.5.x this happened to be tolerated: the empty read
	  surfaced as SSL_ERROR_SYSCALL with an empty error queue (errno 0), which
	  gstdtlsconnection's handle_error explicitly ignores and retries.
	  OpenSSL 4.0.0 stopped allowing it. Commit
	  be42447469dcccc68b7e115c7947e3c25124f3f2 "Fix the converters between the old and
	  new BIO_read functions to handle end-of-file state properly"
	  (PR openssl/openssl#29290, first released in 4.0.0) reworked bread_conv: when an
	  old-style read returns 0 and BIO_CTRL_EOF reports not-at-EOF it now sets
	  BIO_FLAGS_AUTO_EOF, and BIO_eof returns 1 whenever that flag is set.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12191>

2026-07-29 15:20:40 +0900  Seungha Yang <seungha@centricular.com>

	* gst/closedcaption/gsth265reorder.c:
	  h265seiinserter: Fix HEVC with alpha stream handling
	  Ignore NAL units with non-zero nuh_layer_id, as h265decoder does,
	  applying the same change as
	  https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/11144
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12189>

2026-07-17 12:01:06 +0300  Sebastian Dröge <sebastian@centricular.com>

	* ext/resindvd/gstmpegdemux.c:
	  resindvd: mpegpsdemux: Port parse_psm() to byte readers
	  Apply 948b87bf15 here too.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12183>

2026-07-17 11:13:44 +0300  Sebastian Dröge <sebastian@centricular.com>

	* ext/resindvd/gstmpegdemux.c:
	  resindvd: mpegpsdemux: Port over byte reader changes from the main plugin
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12183>

2026-07-16 15:34:02 +0300  Sebastian Dröge <sebastian@centricular.com>

	* gst/mpegdemux/gstmpegdemux.c:
	  mpegpsdemux: Use byte readers for parsing data and make sure enough data is available
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12183>

2026-07-21 15:35:44 +0530  Nirbheek Chauhan <nirbheek@centricular.com>

	* meson.build:
	  meson: Make the g-ir-scanner init section consistent across modules
	  We weren't disabling the registry correctly due to typos and missing
	  env vars.
	  This speeds up introspection builds considerably on Windows.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12163>

2026-07-21 15:32:45 -0400  Nicolas Dufresne <nicolas.dufresne@collabora.com>

	* gst/mpegtsdemux/tsdemux.c:
	  tsdemux: Don't assert if stream pad was not yet created
	  Fix an assert when a continuity missmatch is detected for a stream for which its
	  pad is not yet exposed.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12162>

2026-07-20 16:51:43 +0900  Jihoon Lee <ejihoon.lee@lge.com>

	* gst-libs/gst/wayland/gstwlvideobufferpool.c:
	  wlvideobufferpool: Fix memory leak in gst_wl_video_buffer_pool_alloc_buffer
	  Fix dma_mem leak on buffer too small path in gst_wl_video_buffer_pool_alloc_buffer()
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12160>

2026-07-14 04:01:10 +0530  Nirbheek Chauhan <nirbheek@centricular.com>

	* sys/applemedia/vtdec.c:
	  vtdec: Don't register the hw-only variant on simulators
	  Simulators *never* expose a hardware decoder in the VT APIs. It is
	  always a software decoder, even if the implementation might be backed
	  by a hardware decoder on the host system.
	  This was tested on iOS and tvOS Simulators on an M4 Mac Mini, M1 Mac
	  Mini, and a 2014 Intel Mac Mini.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12112>

2026-07-16 21:31:45 +0200  Diego Nieto <dnieto@fluendo.com>

	* gst-libs/gst/codecparsers/gsth266parser.c:
	  h266parser: fix SEI parsing error handler
	  Clear the partially parsed SEI message in case of an error to
	  prevent memory leaks and avoid processing stale data.
	  Fixes #5219
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12132>

2026-04-10 19:50:06 -0400  Olivier Crête <olivier.crete@collabora.com>

	* ext/tflite/gsttfliteinference.c:
	  tflifeinference: Fix leaks
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/11404>

2026-07-13 18:47:16 +0300  Sebastian Dröge <sebastian@centricular.com>

	* gst/dvdspu/gstspu-vobsub.c:
	  dvdspu: Fix too strict off-by-one bounds check in a couple of places
	  This prevented reading the last byte in some cases.
	  Also add a missing bounds check to a debug function that is not compiled in by
	  default, so is actually not really important at all.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12126>

2026-07-16 13:45:51 +0300  Sebastian Dröge <sebastian@centricular.com>

	* gst/pnm/gstpnmdec.c:
	  pnmdec: Fix out-of-bounds write with bitmap PNM files and non-multiple-of-8 resolutions
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12124>

2026-07-16 13:42:04 +0300  Sebastian Dröge <sebastian@centricular.com>

	* gst/pnm/gstpnmdec.c:
	  pnmdec: Use correct return value for negotiation failure
	  This returns GstFlowReturn and FALSE equals to GST_FLOW_OK.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12124>

2026-07-16 13:31:58 +0300  Sebastian Dröge <sebastian@centricular.com>

	* gst/pnm/gstpnmdec.c:
	  pnmdec: Don't flush more data from the adapter than is available
	  Instead wait for future data.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12124>

2026-07-16 13:31:26 +0300  Sebastian Dröge <sebastian@centricular.com>

	* gst/pnm/gstpnmdec.c:
	  pnmdec: Don't assert if creating the output state fails
	  This can happen e.g. if the resolution is too large for the given format.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12124>

2026-07-08 19:30:19 +0800  He Junyan <junyan.he@intel.com>

	* sys/va/gstvavp9enc.c:
	  va: vp9enc: Mark super frame as corrupt when any frame is corrupt
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12123>

2026-07-08 19:24:14 +0800  He Junyan <junyan.he@intel.com>

	* sys/va/gstvaav1enc.c:
	  va: av1enc: Mark TU as corrupt when any frame is corrupt
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12123>

2026-07-08 15:02:16 +0200  Maksim Nikolaev <maksim.nikolaev.dev@gmail.com>

	* sys/va/gstvabaseenc.c:
	* sys/va/gstvaencoder.c:
	* sys/va/gstvaencoder.h:
	  va: recover from corrupt or overflowing coded buffers
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12123>

2026-07-08 15:01:42 +0200  Maksim Nikolaev <maksim.nikolaev.dev@gmail.com>

	* sys/va/gstvaav1enc.c:
	* sys/va/gstvabaseenc.c:
	* sys/va/gstvabaseenc.h:
	* sys/va/gstvah264enc.c:
	* sys/va/gstvah265enc.c:
	* sys/va/gstvavp8enc.c:
	* sys/va/gstvavp9enc.c:
	  va: size the coded buffer for the CBR bitrate budget
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12123>

2026-07-13 15:24:31 +1000  Matthew Waters <matthew@centricular.com>

	* gst-libs/gst/vulkan/gstvktrash.c:
	  vulkantrash: avoid reinitializing trash objects multiple times
	  Fixes a leak of miniobject private data.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12117>

2026-07-13 16:02:34 +1000  Matthew Waters <matthew@centricular.com>

	* gst-libs/gst/vulkan/gstvkformat.c:
	  vulkan/format: add 3-plane i420 format
	  mesa/amd chooses this format for I420.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12117>

2026-07-16 09:00:50 +1000  Jan Schmidt <jan@centricular.com>

	* sys/d3d11/gstd3d11winrtcapture.cpp:
	  d3d11winrtcapture: Fix incorrect capture height
	  Fix a typo where capture_height would not get properly
	  assigned. Fixes invalid copy region errors.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12115>

2026-07-14 18:15:07 +0530  Nirbheek Chauhan <nirbheek@centricular.com>

	* docs/meson.build:
	  docs: Fix build when mse library is disabled
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12113>

2026-07-08 10:30:35 +0300  Sebastian Dröge <sebastian@centricular.com>

	* gst/videoparsers/gstvc1parse.c:
	  vc1parse: Set has_timing_info() / syncable() in start()
	  The values are reset in PAUSED->READY so setting them only in instance init is
	  not enough.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12102>

2026-07-08 10:29:59 +0300  Sebastian Dröge <sebastian@centricular.com>

	* gst/pcapparse/gstirtspparse.c:
	  irtspparse: Set min frame size in start()
	  The value is reset in PAUSED->READY so setting it only once in instance init is
	  not enough.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12102>

2026-07-10 09:24:27 -0400  Nicolas Dufresne <nicolas.dufresne@collabora.com>

	* ext/gtk/gstgtkwaylandsink.c:
	* ext/wayland/gstwaylandsink.c:
	  waylandsink: Omit reporting drop frame on preroll
	  These sink are a bit special, since they report dropped frame on the next
	  incoming frame. If the sink queue is full when the paused state is reached,
	  the preroll during paused to playing transition will report a drop, which
	  leads to base sink aborting the transition.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12037>

2026-07-07 19:23:32 +0300  Sebastian Dröge <sebastian@centricular.com>

	* gst/videoparsers/gstdiracparse.c:
	* gst/videoparsers/gsth263parse.c:
	  h263parse: diracparse: Sync baseparse configuration with other compressed video parsers
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12096>

2026-07-08 15:41:59 +0200  Albert Sjölund <alberts@axis.com>

	* ext/webrtc/gstwebrtcbin.c:
	  webrtcbin: fix possible floating leak for post-aux
	  The behaviour is different between aux-sender and post-aux-sender. There
	  is a conditional ref_sink if the element is floating in one but not the
	  other. As the element is afterwards added to a bin sink the element
	  before adding.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12085>

2026-07-08 23:48:39 +0200  Tim-Philipp Müller <tim@centricular.com>

	* meson.build:
	  Back to development after 1.28.5

=== release 1.28.5 ===

2026-07-08 23:42:39 +0200  Tim-Philipp Müller <tim@centricular.com>

	* gst-plugins-bad.doap:
	* meson.build:
	  Release 1.28.5

2026-06-26 11:45:51 +0300  Sebastian Dröge <sebastian@centricular.com>

	* gst/librfb/rfbdecoder.c:
	  rfbsrc: Read the correct number of bytes for color values
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12077>

2026-06-26 11:19:41 +0300  Sebastian Dröge <sebastian@centricular.com>

	* gst/librfb/rfbdecoder.c:
	  rfbsrc: Use correct bpp for copying hextile data
	  Fix provided by Clouditera Security, who also reported this.
	  Fixes https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5173
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12077>

2026-06-25 11:47:44 +0300  Sebastian Dröge <sebastian@centricular.com>

	* ext/dtls/gstdtlsconnection.c:
	  dtlsconnection: Allocate large enough buffer for the peer certificate subject DN
	  Fix provided by Clouditera Security.
	  Fixes https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5172
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12076>

2026-06-25 11:18:53 +0300  Sebastian Dröge <sebastian@centricular.com>

	* ext/webrtc/webrtcsdp.c:
	  webrtcsdp: Fix inverted fingerprint existence logic
	  Fix provided by Clouditera Security, who also reported this.
	  Fixes https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5171
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12075>

2026-06-24 11:00:43 +0300  Sebastian Dröge <sebastian@centricular.com>

	* gst/closedcaption/ccutils.c:
	* gst/closedcaption/gstccconverter.c:
	  ccconverter: Use truncated length when converting CEA608 raw to CEA708 CDP
	  Also make sure no caller passes too much data to cc_buffer_push_separated()
	  and truncate internally to the absolute maximum.
	  Fixes https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5161
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12074>

2026-06-24 09:58:28 +0300  Sebastian Dröge <sebastian@centricular.com>

	* gst-libs/gst/codecparsers/gstvp9parser.c:
	  vp9parser: Check that enough data is available for parsing superframe info
	  Fixes https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5160
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12073>

2026-06-22 14:02:28 +0300  Sebastian Dröge <sebastian@centricular.com>

	* gst-libs/gst/codecparsers/gsth266parser.c:
	  h266parser: Check bounds before writing to CTU entrypoint array
	  Fixes https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5156
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12070>

2026-06-22 13:44:29 +0300  Sebastian Dröge <sebastian@centricular.com>

	* gst-libs/gst/codecparsers/gsth266parser.c:
	  h266parser: Avoid out-of-bounds read if too many exp slices are signalled
	  Fixes https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5155
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12069>

2026-06-22 13:44:12 +0300  Sebastian Dröge <sebastian@centricular.com>

	* gst-libs/gst/codecparsers/gsth266parser.c:
	  h266parser: Fix typos in warning messages
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12069>

2026-06-17 11:04:05 +0300  Sebastian Dröge <sebastian@centricular.com>

	* gst/videoparsers/gstmpeg4videoparse.c:
	  mpeg4videoparse: Ensure enough config data is available before extracting profile/level
	  Patch provided by Ramesh Adhikari, who also reported this.
	  Fixes https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5110
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12057>

2026-07-03 08:30:32 +0900  Seungha Yang <seungha@centricular.com>

	* gst-libs/gst/d3d12/gstd3d12device.cpp:
	  d3d12: Fix command list leak
