Opened 8 months ago

Closed 8 months ago

#22827 closed enhancement (fixed)

Backport the fix for CVE-2026-2447 to libvpx

Reported by: Douglas R. Reno Owned by: Joe Locash
Priority: high Milestone: 13.0
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

The fix for this vulnerability was committed to the repository after libvpx-1.16.0 was released. This is a heap buffer overflow that's known to lead to remote code execution when browsing the internet in a web browser.

Because we use this in Firefox and Thunderbird, this should be treated as urgent.

The fix can be found at ​https://chromium.googlesource.com/webm/libvpx/+/d5f35ac8d93cba7f7a3f7ddb8f9dc8bd28f785e1%5E%21/

Change History (3)

comment:1 by Joe Locash, 8 months ago

Owner: changed from blfs-book to Joe Locash
Status: new → assigned

comment:2 by Joe Locash, 8 months ago

Fixed at 2cbe1dfc9f.

Leaving open for security advisory.

Version 1.16.0 did have an ABI change so if updating a 12.4 box the same patch can be used with 1.15.2.

comment:3 by Douglas R. Reno, 8 months ago

Resolution: → fixed
Status: assigned → closed

SA-12.4-100 issued

Thank you Joe!

Note: See TracTickets for help on using tickets.