Denial of Service Vulnerability in GStreamer mkv Demuxing by Freedesktop
CVE-2022-1924
What is CVE-2022-1924?
A denial of service vulnerability has been identified in the GStreamer mkv demuxing process due to an integer overflow in the lzo decompression function within the matroskademux element. This vulnerability can lead to a segfault or potentially overwrite the heap, depending on the memory management capabilities of the libc implementation and the underlying operating system. Specifically, if the system uses libc that employs mmap for managing memory chunks and that the operating system supports mmap, it will likely result in a segfault. In contrast, other scenarios where system constraints do not support these features can result in critical heap overwrites, risking application stability and exposing systems to further attacks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
GStreamer 1.20.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
