CVE-2024-31578: Use After Free
Published Apr 17, 2024
·Updated
FFmpeg version n6.1.1 was discovered to contain a heap use-after-free via the avhwframectxinit function.
Affected Software
10 affected componentsFixes available
ubuntu/ffmpeg<7:3.4.11-0ubuntu0.1+
7:3.4.11-0ubuntu0.1+
ubuntu/ffmpeg<7:4.2.7-0ubuntu0.1+
7:4.2.7-0ubuntu0.1+
ubuntu/ffmpeg<7:4.4.2-0ubuntu0.22.04.1+
7:4.4.2-0ubuntu0.22.04.1+
ubuntu/ffmpeg<7:6.0-6ubuntu1.1
7:6.0-6ubuntu1.1
ubuntu/ffmpeg<7:6.1.1-3ubuntu5+
7:6.1.1-3ubuntu5+
debian/ffmpeg<=7:4.3.6-0+deb11u1, <=7:4.3.7-0+deb11u1, <=7:5.1.5-0+deb12u1, <=7:6.1.1-4, <=7:6.1.1-5
FFmpeg FFmpeg<7.0
Fedoraproject Fedora=38
Fedoraproject Fedora=39
Fedoraproject Fedora=40
Remediation
Event History
Apr 17, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
RemedyAffected Software
Jun 27, 2024
Data Sourced
via Launchpad·07:04 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-31578?
CVE-2024-31578 is classified as a critical vulnerability due to its potential to cause a heap use-after-free condition.
2
How do I fix CVE-2024-31578?
To mitigate CVE-2024-31578, you should upgrade to a fixed version of FFmpeg as specified for your distribution.
3
Which versions of FFmpeg are affected by CVE-2024-31578?
FFmpeg version n6.1.1 is specifically affected by CVE-2024-31578, as well as other versions prior to the recommended remedial updates.
4
What platforms are impacted by CVE-2024-31578?
CVE-2024-31578 impacts Ubuntu and Debian distributions, particularly the outlined versions of the FFmpeg package.
5
Is there a known exploit for CVE-2024-31578?
While specific exploits for CVE-2024-31578 were not publicly disclosed, the nature of the vulnerability could lead to exploitation if left unpatched.