Bug#1106689: libvpx: double-free in vpx_codec_enc_init_multi
From Salvatore Bonaccorso@21:1/5 to Salvatore Bonaccorso on Tue May 27 23:20:01 2025
On Tue, May 27, 2025 at 10:52:40PM +0200, Salvatore Bonaccorso wrote:
Source: libvpx
Version: 1.12.0-1
Severity: grave
Tags: security upstream
Justification: user security hole
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Control: found -1 1.15.0-2
Hi
The recent MFSA's for firefox mention the following issue as critical:
| A double-free could have occurred in vpx_codec_enc_init_multi after a
| failed allocation when initializing the encoder for WebRTC. This could
| have caused memory corruption and a potentially exploitable crash.