FFmpeg prior to commit bf814 was discovered to contain an out of bounds read via the dist->alphabet_size variable in the read_vlc_prefix() function. https://github.com/FFmpeg/FFmpeg/commit/bf814387f42e9b0dea9d75c03db4723c88e7d962 https://patchwork.ffmpeg.org/project/ffmpeg/patch/20231013014959.536776-1-leo.izen@gmail.com/ https://patchwork.ffmpeg.org/project/ffmpeg/patch/20231015004924.597746-1-leo.izen@gmail.com/
Created chromium tracking bugs for this issue: Affects: epel-all [bug 2246966] Created ffmpeg tracking bugs for this issue: Affects: fedora-all [bug 2246965] Created qt5-qtwebengine tracking bugs for this issue: Affects: epel-all [bug 2246967] Affects: fedora-all [bug 2246968] Created qt6-qtwebengine tracking bugs for this issue: Affects: fedora-all [bug 2246969]
This affects 6.1, where this code was added. 6.1.1 contains the fix.