Your message dated Wed, 28 May 2025 04:52:11 +0000 with message-id <E1uK8lv-00GrHn-U5@fasolo.debian.org> and subject line Bug#1106689: fixed in libvpx 1.15.0-2.1 has caused the Debian Bug report #1106689, regarding libvpx: double-free in vpx_codec_enc_init_multi to be marked as done. This means that you claim that the problem has been dealt with. If this is not the case it is now your responsibility to reopen the Bug report if necessary, and/or fix the problem forthwith. (NB: If you are a system administrator and have no idea what this message is talking about, this may indicate a serious mail system misconfiguration somewhere. Please contact owner@bugs.debian.org immediately.) -- 1106689: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1106689 Debian Bug Tracking System Contact owner@bugs.debian.org with problems
--- Begin Message ---
- To: Debian Bug Tracking System <submit@bugs.debian.org>
- Subject: libvpx: double-free in vpx_codec_enc_init_multi
- From: Salvatore Bonaccorso <carnil@debian.org>
- Date: Tue, 27 May 2025 22:52:40 +0200
- Message-id: <[🔎] 174837916018.2946179.8529869495277177517.reportbug@eldamar.lan>
Source: libvpx Version: 1.12.0-1 Severity: grave Tags: security upstream Justification: user security hole X-Debbugs-Cc: carnil@debian.org, Debian Security Team <team@security.debian.org> Control: found -1 1.15.0-2 Hi The recent MFSA's for firefox mention the following issue as critical: | A double-free could have occurred in vpx_codec_enc_init_multi after a | failed allocation when initializing the encoder for WebRTC. This could | have caused memory corruption and a potentially exploitable crash. Cf. https://www.mozilla.org/en-US/security/advisories/mfsa2025-44/ Fix is at: https://chromium.googlesource.com/webm/libvpx/+/1c758781c428c0e895645b95b8ff1512b6bdcecb Regards, Salvatore
--- End Message ---
--- Begin Message ---
- To: 1106689-close@bugs.debian.org
- Subject: Bug#1106689: fixed in libvpx 1.15.0-2.1
- From: Debian FTP Masters <ftpmaster@ftp-master.debian.org>
- Date: Wed, 28 May 2025 04:52:11 +0000
- Message-id: <E1uK8lv-00GrHn-U5@fasolo.debian.org>
- Reply-to: Salvatore Bonaccorso <carnil@debian.org>
Source: libvpx Source-Version: 1.15.0-2.1 Done: Salvatore Bonaccorso <carnil@debian.org> We believe that the bug you reported is fixed in the latest version of libvpx, which is due to be installed in the Debian FTP archive. A summary of the changes between this version and the previous one is attached. Thank you for reporting the bug, which will now be closed. If you have further comments please address them to 1106689@bugs.debian.org, and the maintainer will reopen the bug report if appropriate. Debian distribution maintenance software pp. Salvatore Bonaccorso <carnil@debian.org> (supplier of updated libvpx package) (This message was generated automatically at their request; if you believe that there is a problem with it please contact the archive administrators by mailing ftpmaster@ftp-master.debian.org) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 27 May 2025 23:00:58 +0200 Source: libvpx Architecture: source Version: 1.15.0-2.1 Distribution: unstable Urgency: medium Maintainer: Debian Multimedia Maintainers <debian-multimedia@lists.debian.org> Changed-By: Salvatore Bonaccorso <carnil@debian.org> Closes: 1106689 Changes: libvpx (1.15.0-2.1) unstable; urgency=medium . * Non-maintainer upload. * vpx_codec_enc_init_multi: fix double free on init failure (Closes: #1106689) Checksums-Sha1: 0240f677dc3f16506891623ba17ac8f9347c3469 2388 libvpx_1.15.0-2.1.dsc 9fda6cfb42a2e1b579d1585404faa7c06d77a604 14096 libvpx_1.15.0-2.1.debian.tar.xz Checksums-Sha256: 2d41548d2bdb4d0b13428367642c27d7840fdf3a3d7c32c31a88d249e5289d66 2388 libvpx_1.15.0-2.1.dsc 269e4f3c22dc9a930fa0bd160f45d10ced3ea21ac01361c707f89e0cb29c83dd 14096 libvpx_1.15.0-2.1.debian.tar.xz Files: fc73ca4573937c68e305089690edeee3 2388 video optional libvpx_1.15.0-2.1.dsc c5b56878d9e9346b0b9af2cf4ac9d563 14096 video optional libvpx_1.15.0-2.1.debian.tar.xz -----BEGIN PGP SIGNATURE----- iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmg2K4VfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk ZWJpYW4ub3JnAAoJEAVMuPMTQ89ELnsP/R/gW5nE/MS1D1yOn5wojmOByVANOE6e Ei5gFZZ9HkN4+q/YBT3vD/Y6dzi4NzM4Z4OJHa16EwG/6d5Hwyyw+EfhZXfiPw3e 7joCqk9ow/mTIFTcMALkkkArzaGQVHCEx4qxcpePKdc1FLWe4ZSQmopRKv+Em9OS prZxiq88rtAl65rLbnmVBQs4nScNyXMSYmoBtGtZ+WzSTf5zF+DGJIDPKAodYahY N6DEHavhby/MJmVGYu5v1wODxRfoftCLdoYQ++SWbEhyqEP+mRVo5YIR5Tf2xc5A XhIPRakPi//wkBlBNgh0wQBHsYOGR1vKI49BZmC3sLOjZEfCMVTRS8Z79/Vr/2i3 /phLCdJ22l++AkuXlf3dqPz5vIedDqrTxQ/AzdqhLd6OchHFWHEWZDsvklxrP/En Z3aoR/JRyX72Ep7i4MvldPd/lX+SUtO/XSFxCz48YMtN8vETutlEu8EvLKRy5V/F uAr4k/vETEzC7H2efo4DlHuPEUCcNMNmSsj3foNxjh98qTHTC5nXvcNn7EON/g2e gsH9MXSb3OxZuh0FSAVTmN2SIhbgV8I9mIKeHCRIXiwUM9luBtQhKAtNHH7wFvr3 eDb//OaFUQDHG5QWe8UzgP5Vdj+4QRGKFkVmRw46wU8w2WSS6bkIEfie4WS8kECT K55leMhtDgrY =2IqX -----END PGP SIGNATURE-----Attachment: pgpRv30agnv8a.pgp
Description: PGP signature
--- End Message ---