CVE Vulnerabilities

CVE-2024-35368

Double Free

Published: Nov 29, 2024 | Modified: Nov 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

FFmpeg n7.0 is affected by a Double Free via the rkmpp_retrieve_frame function within libavcodec/rkmppdec.c.

Weakness

The product calls free() twice on the same memory address.

Affected Software

NameVendorStart VersionEnd Version
FfmpegFfmpeg7.0 (including)7.0 (including)
FfmpegUbuntuesm-apps/bionic*
FfmpegUbuntuesm-apps/focal*
FfmpegUbuntuesm-apps/jammy*
FfmpegUbuntuesm-apps/noble*
FfmpegUbuntufocal*
FfmpegUbuntujammy*
FfmpegUbuntunoble*
FfmpegUbuntuoracular*
FfmpegUbuntuupstream*
LibavUbuntutrusty/esm*

Potential Mitigations

References