aom_image.c in libaom in AOMedia before 2021-04-07 frees memory that is not located on the heap.
The product attempts to return a memory resource to the system, but it calls the wrong release function or calls the appropriate release function incorrectly.
Link | Tags |
---|---|
https://bugs.chromium.org/p/aomedia/issues/detail?id=2998 | third party advisory permissions required |
https://aomedia.googlesource.com/aom/+/4efe20e99dcd9b6f8eadc8de8acc825be7416578 | third party advisory patch |
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZXCI33HXH6YSOGC2LPE2REQLMIDH6US4/ | vendor advisory |
https://lists.debian.org/debian-lts-announce/2023/09/msg00003.html | mailing list |
https://www.debian.org/security/2023/dsa-5490 | vendor advisory |
https://security.gentoo.org/glsa/202401-32 | vendor advisory |