yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2021-32278
Component Overview
Vulnerability Overview
Name
CVE-2021-32278
Source
NVD (
link
)
Debian (
link
)
Description
An issue was discovered in faad2 through 2.10.0. A heap-buffer-overflow exists in the function lt_prediction located in lt_predict.c. It allows an attacker to cause code Execution.
CWEs
CWE-787
Published Date
Sep 20, 2021
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://github.com/knik0/faad2/issues/62
Exploit
https://lists.debian.org/debian-lts-announce/2021/10/msg00020.html
Mailing List
https://www.debian.org/security/2022/dsa-5109
Third Party Advisory
https://github.com/knik0/faad2/issues/62
Exploit
https://lists.debian.org/debian-lts-announce/2021/10/msg00020.html
Mailing List
https://www.debian.org/security/2022/dsa-5109
Third Party Advisory
Analysis
#
Affected Component
Analysis
faad2
Patched
Vulnerability Ratings
#
7.8
CVSSv31
6.8
CVSSv2
Others affected components
#
Name
Project
Project Version
Version
Status
faad2
buildroot
2025.02.x
2.11.1
Not Affected
faad2
buildroot
master
2.11.2
Not Affected
faad2
yocto
master
2.11.2+git
Not Affected
faad2
yocto
scarthgap
2.11.1+git
Not Affected
Resolved with patches
#
faad2 (yocto:kirkstone)
#
Title
Author
Resolve
1
Check return value of ltp_data.
Andrew Wesie <awesie@gmail.com>
CVE-2021-32278