Re: obs 30.2.0 or later: double-free on exit

Alan Coopersmith <[email protected]> Fri, 26 Jul 2024 10:41:21 -0700
Newsgroups dev.linux.lists.distributions
Message-ID <[email protected]>
On 7/26/24 01:28, Đoàn Trần Công Danh wrote:
> I'm not sure if this mail should be sent to distros@
> If yes, please help me forward it!

If you mean [email protected], then no, this mail should not be sent
there.   That mailing list is only for non-public, temporarily-embargoed
security information to be shared a short time before it goes public.

Since you've already made this public at
  https://github.com/obsproject/obs-studio/issues/11029
  https://lore.kernel.org/distributions/[email protected]/T/#u
it doesn't belong on the non-public distros list.

You could instead share it with the oss-security list that is the public
counterpart to distros (one of the requirements for sending to the distros
list is that the information be sent to the oss-security list after the
embargo ends).

But since I'm not familiar with obs-studio, I don't know if there's any
actual security exposure here to make it on-topic for the oss-security
mailing list.  While you've described a bug that can crash the program,
what can an attacker do to exploit it?  What will the attacker be able
to do that they couldn't already do?

-- 
         -Alan Coopersmith-                 [email protected]
          Oracle Solaris Engineering - https://blogs.oracle.com/solaris