Logo
vulnerabilityCVE-2021-32276
Name
CVE-2021-32276
Source
NVD ( link)Debian ( link)
Description
An issue was discovered in faad2 through 2.10.0. A NULL pointer dereference exists in the function get_sample() located in output.c. It allows an attacker to cause Denial of Service.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
faad2
Patched

Vulnerability Ratings#


5.5
CVSSv31
4.3
CVSSv2

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
2.11.1
Not Affected
buildroot
master
2.11.2
Not Affected
yocto
master
2.11.2+git
Not Affected
yocto
scarthgap
2.11.1+git
Not Affected

Resolved with patches#


faad2 (yocto:kirkstone)

#
Title
Author
Resolve
1
Check for error after each channel decode.
Andrew Wesie <awesie@gmail.com>
CVE-2021-32276
2
Check for inconsistent number of channels.
Andrew Wesie <awesie@gmail.com>
CVE-2021-32276