CVE Vulnerabilities

CVE-2024-35368

Double Free

Published: Nov 29, 2024 | Modified: Jun 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io minimus.io echohq.com

FFmpeg n7.0 is affected by a Double Free via the rkmpp_retrieve_frame function within libavcodec/rkmppdec.c.

Weakness

The product calls free() twice on the same memory address, potentially leading to modification of unexpected memory locations.

Affected Software

Name Vendor Start Version End Version
Ffmpeg Ffmpeg 7.0 (including) 7.0 (including)
Ffmpeg Ubuntu esm-apps/bionic *
Ffmpeg Ubuntu esm-apps/focal *
Ffmpeg Ubuntu esm-apps/jammy *
Ffmpeg Ubuntu esm-apps/noble *
Ffmpeg Ubuntu focal *
Ffmpeg Ubuntu jammy *
Ffmpeg Ubuntu noble *
Ffmpeg Ubuntu oracular *
Ffmpeg Ubuntu upstream *
Libav Ubuntu trusty/esm *

Potential Mitigations

References