CVE Vulnerabilities

CVE-2024-35368

Double Free

Published: Nov 29, 2024 | Modified: Dec 02, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

FFmpeg n7.0 is affected by a Double Free via the rkmpp_retrieve_frame function within libavcodec/rkmppdec.c.

Weakness

The product calls free() twice on the same memory address, potentially leading to modification of unexpected memory locations.

Affected Software

Name Vendor Start Version End Version
Ffmpeg Ubuntu upstream *
Libav Ubuntu trusty/esm *

Potential Mitigations

References