vulnerability

SUSE: CVE-2022-48434: SUSE Linux Security Advisory

Severity
9
CVSS
(AV:N/AC:M/Au:N/C:C/I:C/A:C)
Published
2023-03-29
Added
2023-05-03
Modified
2025-01-28

Description

libavcodec/pthread_frame.c in FFmpeg before 5.1.2, as used in VLC and other products, leaves stale hwaccel state in worker threads, which allows attackers to trigger a use-after-free and execute arbitrary code in some circumstances (e.g., hardware re-initialization upon a mid-video SPS change when Direct3D11 is used).

Solution(s)

suse-upgrade-ffmpegsuse-upgrade-ffmpeg-4suse-upgrade-ffmpeg-4-libavcodec-develsuse-upgrade-ffmpeg-4-libavdevice-develsuse-upgrade-ffmpeg-4-libavfilter-develsuse-upgrade-ffmpeg-4-libavformat-develsuse-upgrade-ffmpeg-4-libavresample-develsuse-upgrade-ffmpeg-4-libavutil-develsuse-upgrade-ffmpeg-4-libpostproc-develsuse-upgrade-ffmpeg-4-libswresample-develsuse-upgrade-ffmpeg-4-libswscale-develsuse-upgrade-ffmpeg-4-private-develsuse-upgrade-ffmpeg-private-develsuse-upgrade-libavcodec-develsuse-upgrade-libavcodec57suse-upgrade-libavcodec57-32bitsuse-upgrade-libavcodec58_134suse-upgrade-libavcodec58_134-32bitsuse-upgrade-libavdevice-develsuse-upgrade-libavdevice57suse-upgrade-libavdevice57-32bitsuse-upgrade-libavdevice58_13suse-upgrade-libavdevice58_13-32bitsuse-upgrade-libavfilter-develsuse-upgrade-libavfilter6suse-upgrade-libavfilter6-32bitsuse-upgrade-libavfilter7_110suse-upgrade-libavfilter7_110-32bitsuse-upgrade-libavformat-develsuse-upgrade-libavformat57suse-upgrade-libavformat57-32bitsuse-upgrade-libavformat58_76suse-upgrade-libavformat58_76-32bitsuse-upgrade-libavresample-develsuse-upgrade-libavresample3suse-upgrade-libavresample3-32bitsuse-upgrade-libavresample4_0suse-upgrade-libavresample4_0-32bitsuse-upgrade-libavutil-develsuse-upgrade-libavutil55suse-upgrade-libavutil55-32bitsuse-upgrade-libavutil56_70suse-upgrade-libavutil56_70-32bitsuse-upgrade-libpostproc-develsuse-upgrade-libpostproc54suse-upgrade-libpostproc54-32bitsuse-upgrade-libpostproc55_9suse-upgrade-libpostproc55_9-32bitsuse-upgrade-libswresample-develsuse-upgrade-libswresample2suse-upgrade-libswresample2-32bitsuse-upgrade-libswresample3_9suse-upgrade-libswresample3_9-32bitsuse-upgrade-libswscale-develsuse-upgrade-libswscale4suse-upgrade-libswscale4-32bitsuse-upgrade-libswscale5_9suse-upgrade-libswscale5_9-32bit
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.