﻿id	summary	reporter	owner	description	type	status	priority	milestone	component	version	severity	resolution	keywords	cc
22827	Backport the fix for CVE-2026-2447 to libvpx	Douglas R. Reno	Joe Locash	"The fix for this vulnerability was committed to the repository after libvpx-1.16.0 was released. This is a heap buffer overflow that's known to lead to remote code execution when browsing the internet in a web browser.

Because we use this in Firefox and Thunderbird, this should be treated as urgent.

The fix can be found at https://chromium.googlesource.com/webm/libvpx/+/d5f35ac8d93cba7f7a3f7ddb8f9dc8bd28f785e1%5E%21/"	enhancement	closed	high	13.0	BOOK	git	medium	fixed		
