Wind River Support Network

HomeDefectsLIN1022-12125
Fixed

LIN1022-12125 : Security Advisory - ffmpeg - CVE-2024-35369

Created: Nov 30, 2024    Updated: Jun 10, 2025
Resolved Date: May 28, 2025
Found In Version: 10.22.33.1
Fix Version: 10.22.33.21
Severity: Standard
Applicable for: Wind River Linux LTS 22
Component/s: Userspace

Description

In FFmpeg version n6.1.1, specifically within the avcodec/speexdec.c module, a potential security vulnerability exists due to insufficient validation of certain parameters when parsing Speex codec extradata. This vulnerability could lead to integer overflow conditions, potentially resulting in undefined behavior or crashes during the decoding process.

CREATE(Triage):(User=admin) CVE-2024-35369 (https://nvd.nist.gov/vuln/detail/CVE-2024-35369)

CVEs


Live chat
Online