CVE-2024-35365Double Free in Ffmpeg

CWE-415Double Free7 documents6 sources
Severity
8.8HIGHNVD
EPSS
0.2%
top 54.65%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 3
Latest updateOct 15

Description

FFmpeg version n6.1.1 has a double-free vulnerability in the fftools/ffmpeg_mux_init.c component of FFmpeg, specifically within the new_stream_audio function.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages4 packages

debiandebian/ffmpeg< ffmpeg 7:7.0.1-3 (forky)
Debianffmpeg/ffmpeg< 7:7.0.1-3+1
Ubuntuffmpeg/ffmpeg< 7:2.8.17-0ubuntu0.1+esm12+4
NVDffmpeg/ffmpeg6.1.1

Patches

🔴Vulnerability Details

3
OSV
ffmpeg vulnerabilities2025-10-15
OSV
CVE-2024-35365: FFmpeg version n62025-01-03
GHSA
GHSA-63xr-9hmx-v966: FFmpeg version n62025-01-03

📋Vendor Advisories

3
Ubuntu
FFmpeg vulnerabilities2025-10-15
Red Hat
ffmpeg: FFmpeg: Double-free vulnerability in new_stream_audio function2025-01-03
Debian
CVE-2024-35365: ffmpeg - FFmpeg version n6.1.1 has a double-free vulnerability in the fftools/ffmpeg_mux_...2024