yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2022-3109
Component Overview
Vulnerability Overview
Name
CVE-2022-3109
Source
NVD (
link
)
Debian (
link
)
Description
An issue was discovered in the FFmpeg package, where vp3_decode_frame in libavcodec/vp3.c lacks check of the return value of av_malloc() and will cause a null pointer dereference, impacting availability.
CWEs
CWE-476
CWE-476
Published Date
Dec 16, 2022
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://bugzilla.redhat.com/show_bug.cgi?id=2153551
Issue Tracking
https://github.com/FFmpeg/FFmpeg/commit/656cb0450aeb73b25d7d26980af342b37ac4c568
Patch
https://lists.debian.org/debian-lts-announce/2023/06/msg00016.html
Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KOMB6WRUC55VWV25IKJTV22KARBUGWGQ/
Third Party Advisory
https://www.debian.org/security/2023/dsa-5394
Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2153551
Issue Tracking
https://github.com/FFmpeg/FFmpeg/commit/656cb0450aeb73b25d7d26980af342b37ac4c568
Patch
https://lists.debian.org/debian-lts-announce/2023/06/msg00016.html
Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KOMB6WRUC55VWV25IKJTV22KARBUGWGQ/
Third Party Advisory
https://www.debian.org/security/2023/dsa-5394
Third Party Advisory
Analysis
#
Affected Component
Analysis
ffmpeg
Patched
Vulnerability Ratings
#
7.5
CVSSv31
7.5
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
ffmpeg
buildroot
2025.02.x
6.1.5
Not Affected
ffmpeg
buildroot
master
6.1.5
Not Affected
ffmpeg
openwrt
master
6.1.4-r2
Not Affected
ffmpeg
openwrt
openwrt-25.12
6.1.4-r1
Not Affected
ffmpeg
yocto
master
8.1.1
Not Affected
ffmpeg
yocto
scarthgap
6.1.4
Not Affected
Resolved with patches
#
ffmpeg (yocto:kirkstone)
#
Title
Author
Resolve
1
avcodec/vp3: Add missing check for av_malloc
Jiasheng Jiang <jiasheng@iscas.ac.cn>
CVE-2022-3109