CVE-2021-36408: Use After Free
Published Jan 10, 2022
·Updated
An issue was discovered in libde265 v1.0.8.There is a Heap-use-after-free in intrapred.h when decoding file using dec265.
Affected Software
4 affected componentsFixes available
debian/libde265
1.0.11-0+deb11u31.0.11-0+deb11u11.0.11-1+deb12u21.0.15-1
struktur libde265=1.0.8
Debian Debian Linux=10.0
Debian Debian Linux=11.0
Remediation
Event History
Jan 10, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Jan 30, 2024
Data Sourced
via Launchpad·08:52 PM
Description
Sep 14, 2024
Data Sourced
via Ubuntu·09:27 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-36408?
CVE-2021-36408 is classified as a high-severity vulnerability due to the potential for heap-use-after-free leading to arbitrary code execution.
2
How do I fix CVE-2021-36408?
To fix CVE-2021-36408, upgrade to libde265 versions 1.0.11-0+deb11u3, 1.0.11-0+deb11u1, 1.0.11-1+deb12u2, or 1.0.15-1.
3
Which software is affected by CVE-2021-36408?
CVE-2021-36408 affects libde265 version 1.0.8 and prior versions.
4
What type of vulnerability is CVE-2021-36408?
CVE-2021-36408 is a heap-use-after-free vulnerability identified in libde265 during file decoding operations.
5
Is there a known exploit for CVE-2021-36408?
As of now, there are no known public exploits for CVE-2021-36408, but its high severity indicates potential for exploitation.