[CLSA-2026:1787214152] Fix of 5 CVEs
Type:
security
Severity:
Critical
Release date:
2026-08-20 08:22:46 UTC
Description:
* SECURITY UPDATE: double free in vpx_codec_enc_init_multi() when encoder initialisation fails (ELSCVE-171705) - debian/patches/CVE-2025-5283.patch: release ownership of mr_low_res_mode_info when vp8_create_compressor() fails so the buffer is not freed twice, in vp8/vp8_cx_iface.c and vpx/src/vpx_encoder.c. - CVE-2025-5283
Updated packages:
  • libvpx-dev_1.7.0-3ubuntu0.18.04.1+tuxcare.els4_amd64.deb
    sha:cd454e04a3c1ecf35a7b830f89110ea7a0f4910f
  • libvpx-doc_1.7.0-3ubuntu0.18.04.1+tuxcare.els4_all.deb
    sha:ac679eaf2677b40b9112cf09d0c880e8f69154e4
  • libvpx5_1.7.0-3ubuntu0.18.04.1+tuxcare.els4_amd64.deb
    sha:e5b26746be345ecc9c53c538b204a5cb08af4b4b
  • vpx-tools_1.7.0-3ubuntu0.18.04.1+tuxcare.els4_amd64.deb
    sha:b6727705239fa4be193312a01254635268d61c4a
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.