Release date:
2026-08-20 08:22:46 UTC
Description:
* SECURITY UPDATE: double free in vpx_codec_enc_init_multi() when
encoder initialisation fails (ELSCVE-171705)
- debian/patches/CVE-2025-5283.patch: release ownership of
mr_low_res_mode_info when vp8_create_compressor() fails so the
buffer is not freed twice, in vp8/vp8_cx_iface.c and
vpx/src/vpx_encoder.c.
- CVE-2025-5283
Updated packages:
-
libvpx-dev_1.7.0-3ubuntu0.18.04.1+tuxcare.els4_amd64.deb
sha:cd454e04a3c1ecf35a7b830f89110ea7a0f4910f
-
libvpx-doc_1.7.0-3ubuntu0.18.04.1+tuxcare.els4_all.deb
sha:ac679eaf2677b40b9112cf09d0c880e8f69154e4
-
libvpx5_1.7.0-3ubuntu0.18.04.1+tuxcare.els4_amd64.deb
sha:e5b26746be345ecc9c53c538b204a5cb08af4b4b
-
vpx-tools_1.7.0-3ubuntu0.18.04.1+tuxcare.els4_amd64.deb
sha:b6727705239fa4be193312a01254635268d61c4a
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.