CVE-2024-35368

FFmpeg n7.0 is affected by a Double Free via the rkmpp_retrieve_frame function within libavcodec/rkmppdec.c.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ffmpeg:ffmpeg:7.0:*:*:*:*:*:*:*

History

03 Jun 2025, 16:02

Type Values Removed Values Added
References () https://gist.github.com/1047524396/7e6e47220ae2b2d2fb4611f0d8a31ec5 - () https://gist.github.com/1047524396/7e6e47220ae2b2d2fb4611f0d8a31ec5 - Third Party Advisory
References () https://github.com/FFmpeg/FFmpeg/blob/n7.0/libavcodec/rkmppdec.c#L466 - () https://github.com/FFmpeg/FFmpeg/blob/n7.0/libavcodec/rkmppdec.c#L466 - Product
References () https://github.com/ffmpeg/ffmpeg/commit/4513300989502090c4fd6560544dce399a8cd53c - () https://github.com/ffmpeg/ffmpeg/commit/4513300989502090c4fd6560544dce399a8cd53c - Patch
First Time Ffmpeg
Ffmpeg ffmpeg
CPE cpe:2.3:a:ffmpeg:ffmpeg:7.0:*:*:*:*:*:*:*

02 Dec 2024, 17:15

Type Values Removed Values Added
Summary
  • (es) FFmpeg n7.0 se ve afectado por una doble liberación a través de la función rkmpp_retrieve_framework dentro de libavcodec/rkmppdec.c.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-415

29 Nov 2024, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-29 20:15

Updated : 2025-06-03 16:02


NVD link : CVE-2024-35368

Mitre link : CVE-2024-35368

CVE.ORG link : CVE-2024-35368


JSON object : View

Products Affected

ffmpeg

  • ffmpeg
CWE
CWE-415

Double Free