OpenH264 Vulnerability / CVE-2025-27091

As the codec is distributed via cisco’s repo, but IIRC build in fedora’s infra; is the fixed version already in the pipeline? I cant find any bz entry …

https://security-tracker.debian.org/tracker/CVE-2025-27091

The fix is in 2.6.0. There are builds in testing for 2.6.0 that went unpushed:

https://bodhi.fedoraproject.org/updates/?packages=openh264

Looks like it maybe shouldn’t be an issue since Fedora should no longer be packaging it since it’s delivered via Cisco: