CVE-2022-48434
CVSS V2 None
CVSS V3 None
Description
libavcodec/pthread_frame.c in FFmpeg before 5.1.2, as used in VLC and other products, leaves stale hwaccel state in worker threads, which allows attackers to trigger a use-after-free and execute arbitrary code in some circumstances (e.g., hardware re-initialization upon a mid-video SPS change when Direct3D11 is used).
Overview
- CVE ID
- CVE-2022-48434
- Assigner
- cve@mitre.org
- Vulnerability Status
- Modified
- Published Version
- 2023-03-29T17:15:07
- Last Modified Date
- 2023-04-22T03:15:08
Weakness Enumerations
CPE Configuration (Product)
CPE | Vulnerable | Operator | Version Start | Version End |
---|---|---|---|---|
cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:* | 1 | OR | 5.1.2 |
References
Reference URL | Reference Tags |
---|---|
https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/cc867f2c09d2b69cee8a0eccd62aff002cbbfe11 | Mailing List Patch |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KOMB6WRUC55VWV25IKJTV22KARBUGWGQ/ | |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PQHNSWXFUN3VJ3AO2AEJUK3BURSGM5G2/ | |
https://news.ycombinator.com/item?id=35356201 | Exploit Issue Tracking Third Party Advisory |
https://wrv.github.io/h26forge.pdf | Technical Description |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2022-48434 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-48434 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2023-04-17 03:46:19 | Added to TrackCVE | |||
2023-04-17 03:46:21 | Weakness Enumeration | new | ||
2023-04-22 04:01:24 | 2023-04-22T03:15:08 | CVE Modified Date | updated | |
2023-04-22 04:01:28 | References | updated |