GStreamer is the eighth bugfix-and-security maintenance release in the stable 1.28 series. The update closes real memory-safety holes across the SVG decoder, raw-A RTP depayloaders, and buffer handling, while fixing playback regressions that had broken FLAC seeking and HLS/DASH streaming. It also adds two genuine capabilities not in 1.28.7: MXF demuxer support for reading AAF AIFF-AIFC audio and dual-mono encoding in the FFmpeg wrapper. The team says it's safe to upgrade directly from any earlier 1.28.x, with the full changelog available on the GStreamer website.
GStreamer 1.28.8 ships with security fixes and kills a wave of playback regressions
The eighth maintenance release in the stable 1.28 series lands two real additions and closes a pile of memory-safety holes.
GStreamer released 1.28.8 today. That makes it the eighth bugfix-and-security point release in the stable 1.28 branch, which itself opened on 27 January this year. Since 1.28.7 came out only days before, this one is a meaty delta against its immediate predecessor.
The team's message is blunt. Update, they say, and do it soon. Everything in the changelog is new against 1.28.7 by definition, because a .x point release carries nothing forward. No new elements. No new public API. Just risk reduction.
Keep in mind that most of the delta is three things at once: security fixes, playback regressions that surfaced during the 1.28 dev cycle, and crashes scattered across the RTP/RTSP, container, codec, and GPU-plugin stacks. On top of that ride two genuine additions. That's the part that separates this from a cookie-cutter maintenance release.
The security fixes are the headline
Several of them map straight to real-world exploitation paths. Take the rsvgdec plugin, patched for an out-of-bounds read when scanning for the SVG end tag. Not much in isolation, but an attacker feeding a malformed SVG can push a good deal further than intended.
There's also a cluster of raw-A RTP depayloaders, rtpL8depay, rtpL16depay, and rtpL24depay, that would write out of bounds at high channel counts. adpcmenc had its IMA encode loop reading past the end of the input frame, while v4l2 carried a guint overflow in calculate_max_sizeimage. The buffer stack was leaving dangling pointers when memory appends failed, plus NULL pointer dereferences when deserializing reference-timestamp meta.
Net effect: the same memory-safety holes that turn up in every mature media framework, closed out before anyone has to ship a CVE.
Playback, seeking, and the regressions
Slightly less glamorous, but arguably more annoying, this category.
flacparse used to break a valid FLAC file after a seek, throwing "Internal data stream error." That's a regression since 1.28, and resyncing after a seek is now fixed. adaptivedemux2 carried a parallel HLS/DASH playback regression, along with related downloadhelper context-drain crashes that SIGABRT-ed inside downloadhelper_stop(). qtmux now preserves the earliest reordered presentation time, and Windows media audio/video got broader seeking work across the board.
If you've ever chased a seek that silently corrupted your stream, this cluster will feel familiar.
1.28's HLS and DASH elements were among the more ambitious additions in the cycle, and apparently needed trimming before long. Not every ambitious element ages gracefully.
A couple of things you can actually use
Beyond the fixes, 1.28.8 brings two capabilities that weren't in 1.28.7.
The MXF demuxer can now read AAF AIFF-AIFC audio. That's a narrow win, but if you wrangle broadcast masters with AIFF-based audio it's genuinely useful. The second addition is dual-mono handling in the FFmpeg-wrapping encoders. avaudenc fixes an endless drain in flushing encoders and now honors dual mono, avcodecmap accounts for the dual-mono case, and avenc_tta allows up to 16 channels now.
Everything else in the delta
The RTP/RTSP stack gets a solid hardening pass. rtspsrc had a SIGSEGV in gst_rtspsrc_setup_streams_start() whenever an SDP media section lacked an a=control attribute, which could take down an RTSP client mid-setup. rtpsession now ignores SDES priv RTCP packets of invalid length. A batch of smaller depayloader fixes rounds things out.
Container work also fixes the year-2036 timestamp rollover in the ISOBMFF dash/iso/fmp4 muxers. That's the NTP/ISO time-wrap problem that tends to bite only once you've had a project alive long enough to care about it. You have to be maintaining something for years before a 2036 bug starts mattering. matroskamux no longer drops aspect ratio for non-integer PARs, matroskademux stops crashing on bogus xiph codec-data packet sizes, and mxfmux gets a frame-reordering crash fix.
GPU and hardware-acceleration touches round it out: VA-API compositor alpha blending with the Intel driver, AMD AMF AV1 encoder keyframe fixes, nvh264dec top-field POC handling in DPB entries, plus Vulkan H.26x and D3D12 transform_meta work.
Worth it?
The honest read: this is a textbook point release. No features, just fewer ways to crash. Exactly what you want from the 1.28 branch in its eighth bugfix release. The security fixes close real out-of-bounds paths in elements that touch untrusted input. The playback fixes matter to actual users, since the FLAC post-seek error and the adaptivedemux2 regression broke streams that worked before 1.28.
The two additions are small, sure, but they're real deltas over 1.28.7. And neither touches the public API, so upgrading shouldn't break your build.
This was a team effort spanning 29 named authors, Jan Schmidt, Sebastian Dröge, Nicolas Dufresne, Nirbheek Chauhan, Olivier Crête, Seungha Yang, Thibault Saunier, Tim-Philipp Müller, and many others, riding on the usual crowd of bug-filers and testers.
Head here to the release notes and full changelog.
