漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
FFmpeg 4.4 - 8.1.2 Double-Free in NVDEC Hardware Decoder via nvdec.c
Vulnerability Description
FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC hardware decoder within libavcodec/nvdec.c that allows attackers to trigger memory corruption by supplying a crafted video file. When no decoder surfaces remain, the ff_nvdec_start_frame_sep_ref error path frees memory via nvdec_fdd_priv_free while the calling layer subsequently frees the same frame description data, resulting in a double-free of the underlying decoder context in any FFmpeg-based application using NVDEC hardware-accelerated decoding.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Vulnerability Type
双重释放
Vulnerability Title
FFmpeg 资源管理错误漏洞
Vulnerability Description
FFmpeg是FFmpeg组织开源的一套可录制、转换以及流化音视频的完整解决方案。 FFmpeg 4.4版本至8.1.2版本存在资源管理错误漏洞,该漏洞源于libavcodec/nvdec.c中的NVIDIA NVDEC硬件解码器存在双重释放,当解码器表面(decoder surfaces)用尽时,ff_nvdec_start_frame_sep_ref错误路径通过nvdec_fdd_priv_free释放内存,而调用层随后释放相同的帧描述数据,导致底层解码器环境被双重释放,可能允许攻击者通过提供特制视频
CVSS Information
N/A
Vulnerability Type
N/A