Fedora Account System
Red Hat Associate
Red Hat Customer
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process. FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC hardware decoder within libavcodec/nvdec.c that allows attackers to trigger memory corruption by supplying a crafted video file. When no decoder surfaces remain, the ff_nvdec_start_frame_sep_ref error path frees memory via nvdec_fdd_priv_free while the calling layer subsequently frees the same frame description data, resulting in a double-free of the underlying decoder context in any FFmpeg-based application using NVDEC hardware-accelerated decoding.
*** Bug 2519668 has been marked as a duplicate of this bug. ***
This is fixed by master: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/7f0b6476b6ef2d07d163a7d3229f8c9e250112b5 9.0: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/3d5ad47c40436dbdeaaa6601af0bb4575d5aa3c5 8.1: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/9cbcf979a587a66b280496657d00fabe301bf20f 7.1 and 5.1 are affected.