Speaker
Description
In the last months, there has been a lot of reporting on LLM-based tooling easily finding dozens of security vulnerabilities in open source software. Projects like the Linux kernel or curl are well known to have been hit by this heavily, with many discussions about the usefulness and validity of these reports and how this flood of reports can be handled. As GStreamer is used in many safety critical areas and has to handle all kinds of complex data formats coming from untrusted sources, GStreamer is a natural target and affected by this as well.
Just this year alone >80 security vulnerabilities were already fixed while in the previous years we only had a handful of security vulnerability reports to process.
This talk will give an overview of what the situation looks like nowadays for GStreamer: what kind of reports come in and which areas are affected most, how many of the reports are false positives or of low quality, how we process them, and how are we trying to improve the situation for the future.
Speaker Bio
Sebastian works at Centricular on GStreamer and other projects, and has been working on GStreamer for about 20 years.
| Duration of the talk |
|---|
















