Opened 8 months ago
Closed 8 months ago
#22827 closed enhancement (fixed)
Backport the fix for CVE-2026-2447 to libvpx
| Reported by: | Douglas R. Reno | Owned by: | Joe Locash |
|---|---|---|---|
| Priority: | high | Milestone: | 13.0 |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
The fix for this vulnerability was committed to the repository after libvpx-1.16.0 was released. This is a heap buffer overflow that's known to lead to remote code execution when browsing the internet in a web browser.
Because we use this in Firefox and Thunderbird, this should be treated as urgent.
The fix can be found at https://chromium.googlesource.com/webm/libvpx/+/d5f35ac8d93cba7f7a3f7ddb8f9dc8bd28f785e1%5E%21/
Change History (3)
comment:1 by , 8 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:2 by , 8 months ago
comment:3 by , 8 months ago
| Resolution: | → fixed |
|---|---|
| Status: | assigned → closed |
SA-12.4-100 issued
Thank you Joe!
Note:
See TracTickets
for help on using tickets.

Fixed at 2cbe1dfc9f.
Leaving open for security advisory.
Version 1.16.0 did have an ABI change so if updating a 12.4 box the same patch can be used with 1.15.2.