CVE Vulnerabilities

CVE-2022-40515

Double Free

Published: Mar 10, 2023 | Modified: Apr 12, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Memory corruption in Video due to double free while playing 3gp clip with invalid metadata atoms.

Weakness

The product calls free() twice on the same memory address, potentially leading to modification of unexpected memory locations.

Affected Software

Name Vendor Start Version End Version
Apq8009_firmware Qualcomm - (including) - (including)

Potential Mitigations

References