Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

openSUSE: 2025:0862-1 important: ffmpeg-4 Advisory Security Update

opensuse
Calendar Grey March 14, 2025
Dist Opensuse Esm H88
SUSE updates ffmpeg-4 with critical security patches addressing 15 vulnerabilities, including important fixes.
An update that solves 15 vulnerabilities and has three security fixes can now be installed.

Description

This update for ffmpeg-4 fixes the following issues:

* CVE-2025-22921: Fixed segmentation violation in NULL pointer dereference via

the component /libavcodec/jpeg2000dec.c (bsc#1237382).

* CVE-2025-25473: Fixed memory leak in avformat_free_context() (bsc#1237351).

* CVE-2025-0518: Fixed unchecked sscanf return value which leads to memory

data leak (bsc#1236007).

* CVE-2025-22919: Fixed denial of service (DoS) via opening a crafted AAC file

(bsc#1237371).

* CVE-2024-12361: Fixed NULL Pointer Dereference (bsc#1237358).

* CVE-2024-35368: Fixed Double Free via the rkmpp_retrieve_frame function

within libavcodec/rkmppdec.c (bsc#1234028).

* CVE-2024-36613: Fixed Integer overflow in ffmpeg (bsc#1235092).

* CVE-2023-50010: Fixed arbitrary code execution via the set_encoder_id

function in /fftools/ffmpeg_enc.c component (bsc#1223256).

* CVE-2023-51794: Fixed heap-buffer-overflow at libavfilter/af_stereowiden.c

(bsc#1223437).

* CVE-2023-51793: Fixed...

Read the Full Advisory

Patch

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like

YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise Workstation Extension 15 SP6

zypper in -t patch SUSE-SLE-Product-WE-15-SP6-2025-862=1

* openSUSE Leap 15.6

zypper in -t patch SUSE-2025-862=1 openSUSE-SLE-15.6-2025-862=1

* SUSE Package Hub 15 15-SP6

zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP6-2025-862=1

Package List

* SUSE Linux Enterprise Workstation Extension 15 SP6 (x86_64)

* libavcodec58_134-4.4.5-150600.13.16.1

* ffmpeg-4-debuginfo-4.4.5-150600.13.16.1

* libswresample3_9-4.4.5-150600.13.16.1

* libavutil56_70-debuginfo-4.4.5-150600.13.16.1

* libavformat58_76-4.4.5-150600.13.16.1

* libswscale5_9-4.4.5-150600.13.16.1

* libavutil56_70-4.4.5-150600.13.16.1

* libavcodec58_134-debuginfo-4.4.5-150600.13.16.1

* ffmpeg-4-debugsource-4.4.5-150600.13.16.1

* libavformat58_76-debuginfo-4.4.5-150600.13.16.1

* libswscale5_9-debuginfo-4.4.5-150600.13.16.1

* libswresample3_9-debuginfo-4.4.5-150600.13.16.1

* openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586)

* ffmpeg-4-private-devel-4.4.5-150600.13.16.1

* libpostproc55_9-4.4.5-150600.13.16.1

* libpostproc55_9-debuginfo-4.4.5-150600.13.16.1

* libavformat58_76-4.4.5-150600.13.16.1

* libavresample4_0-4.4.5-150600.13.16.1

* libavformat58_76-debuginfo-4.4.5-150600.13.16.1

* ffmpeg-4-libavformat-devel-4.4.5-150600.13.16.1

* ffmpeg-4-libavutil-devel-4.4.5-150600.13.16.1

*...

Read the Full Advisory

References

* bsc#1202848

* bsc#1215945

* bsc#1223070

* bsc#1223235

* bsc#1223256

* bsc#1223272

* bsc#1223304

* bsc#1223437

* bsc#1227296

* bsc#1229026

* bsc#1229338

* bsc#1234028

* bsc#1235092

* bsc#1236007

* bsc#1237351

* bsc#1237358

* bsc#1237371

* bsc#1237382

## References:

* https://www.suse.com/security/cve/CVE-2023-49502.html

* https://www.suse.com/security/cve/CVE-2023-50010.html

* https://www.suse.com/security/cve/CVE-2023-51793.html

* https://www.suse.com/security/cve/CVE-2023-51794.html

* https://www.suse.com/security/cve/CVE-2023-51798.html

* https://www.suse.com/security/cve/CVE-2024-12361.html

* https://www.suse.com/security/cve/CVE-2024-31578.html

* https://www.suse.com/security/cve/CVE-2024-32230.html

* https://www.suse.com/security/cve/CVE-2024-35368.html

* https://www.suse.com/security/cve/CVE-2024-36613.html

* https://www.suse.com/security/cve/CVE-2024-7055.html

* https://www.suse.com/security/cve/CVE-2025-0518.html

* https://www.suse.com/security/cve/CVE-2025-22919.html

*...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2025:0862-1
Release Date: 2025-03-14T08:45:39Z
Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Workstation Extension 15 SP6 * SUSE Package Hub 15 15-SP6

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here