Re: [BLFS Trac] #23381: libde265-1.1.0
| Newsgroups | gmane.linux.lfs.beyond.book |
|---|---|
| Message-ID | <[email protected]> |
#23381: libde265-1.1.0
-------------------------+------------------------
Reporter: Bruce Dubbs | Owner: blfs-book
Type: enhancement | Status: new
Priority: high | Milestone: 13.1
Component: BOOK | Version: git
Severity: normal | Resolution:
Keywords: |
-------------------------+------------------------
Changes (by Douglas R. Reno):
* priority: normal => high
Comment:
{{{
v1.1.0 - security limits
Added de265_security_limits parameters to limit the maximum image size and
memory that
libde265 will use during decoding.
Security fixes
CVE TBD (GHSA-g2rg-wj66-w594) - Out-of-bounds write in
process_reference_picture_set
via predicted short-term RPS
CVE TBD (GHSA-vv8h-932h-7r86) - Heap buffer overflow in
de265_image_get_buffer via
SPS dimension integer overflow
CVE TBD (GHSA-g5hj-rf9f-7vxm) - Unbounded memory accumulation via
orphaned slice
headers in read_slice_NAL
(GHSA-x27c-jp65-g395) - Quadratic CPU consumption in NAL parser
(remove_stuffing_bytes, resize)
}}}
The only thing I can say professionally about GHSA-vv8h-932h-7r86 is:
OUCH. "Massive heap buffer overflow (4 GB write into 1 KB allocation) —
crash, high potential for code execution"
--
Ticket URL: <https://wiki.linuxfromscratch.org/blfs/ticket/23381#comment:1>
BLFS Trac <https://wiki.linuxfromscratch.org/blfs/>
Beyond Linux From Scratch
--
http://lists.linuxfromscratch.org/sympa/info/blfs-book
Unsubscribe: See the above information page