This update for ffmpeg-4 fixes the following issues:
* CVE-2020-22037: Fixed unchecked return value of the init_vlc function
(bsc#1186756)
* CVE-2024-12361: Fixed null pointer dereference (bsc#1237358)
* CVE-2024-35368: Fixed double free via the rkmpp_retrieve_frame function
within libavcodec/rkmppdec.c (bsc#1234028)
* CVE-2024-36613: Fixed integer overflow in the DXA demuxer of the libavformat
library (bsc#1235092)
* CVE-2025-0518: Fixed memory leak due to unchecked sscanf return value
(bsc#1236007)
* CVE-2025-22919: Fixed denial of service (DoS) via opening a crafted AAC file
(bsc#1237371)
* CVE-2025-22921: Fixed segmentation violation in NULL pointer dereference via
the component /libavcodec/jpeg2000dec.c (bsc#1237382)
* CVE-2025-25473: Fixed memory leak in avformat_free_context() (bsc#1237351)
Other fixes:
* Build with SVT-AV1 3.0.0.
* Update to release 4.4.5:
* Adjust bconds to build the package in SLFO without xvidcore.
* Add...
Read the Full Advisory## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* openSUSE Leap 15.4
zypper in -t patch SUSE-2025-1128=1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2025-1128=1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2025-1128=1
* SUSE Linux Enterprise Server 15 SP4 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2025-1128=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2025-1128=1
* openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586)
* libpostproc55_9-debuginfo-4.4.5-150400.3.46.1
* ffmpeg-4-debugsource-4.4.5-150400.3.46.1
* libavcodec58_134-4.4.5-150400.3.46.1
* ffmpeg-4-libavdevice-devel-4.4.5-150400.3.46.1
* ffmpeg-4-libavresample-devel-4.4.5-150400.3.46.1
* ffmpeg-4-libswscale-devel-4.4.5-150400.3.46.1
* libavfilter7_110-debuginfo-4.4.5-150400.3.46.1
* libavformat58_76-4.4.5-150400.3.46.1
* libavutil56_70-debuginfo-4.4.5-150400.3.46.1
* libswresample3_9-debuginfo-4.4.5-150400.3.46.1
* libavresample4_0-4.4.5-150400.3.46.1
* ffmpeg-4-libswresample-devel-4.4.5-150400.3.46.1
* libavdevice58_13-debuginfo-4.4.5-150400.3.46.1
* ffmpeg-4-4.4.5-150400.3.46.1
* ffmpeg-4-debuginfo-4.4.5-150400.3.46.1
* libswscale5_9-debuginfo-4.4.5-150400.3.46.1
* libavcodec58_134-debuginfo-4.4.5-150400.3.46.1
* libavutil56_70-4.4.5-150400.3.46.1
* ffmpeg-4-libavutil-devel-4.4.5-150400.3.46.1
* libpostproc55_9-4.4.5-150400.3.46.1
* ffmpeg-4-libpostproc-devel-4.4.5-150400.3.46.1
*...
Read the Full Advisory* bsc#1186756
* bsc#1202848
* bsc#1215945
* bsc#1219494
* bsc#1229338
* bsc#1230983
* bsc#1234028
* bsc#1235092
* bsc#1236007
* bsc#1237351
* bsc#1237358
* bsc#1237371
* bsc#1237382
* jsc#PED-10024
## References:
* https://www.suse.com/security/cve/CVE-2020-22037.html
* https://www.suse.com/security/cve/CVE-2024-12361.html
* https://www.suse.com/security/cve/CVE-2024-35368.html
* https://www.suse.com/security/cve/CVE-2024-36613.html
* https://www.suse.com/security/cve/CVE-2025-0518.html
* https://www.suse.com/security/cve/CVE-2025-22919.html
* https://www.suse.com/security/cve/CVE-2025-22921.html
* https://www.suse.com/security/cve/CVE-2025-25473.html
* https://bugzilla.suse.com/show_bug.cgi?id=1186756
* https://bugzilla.suse.com/show_bug.cgi?id=1202848
* https://bugzilla.suse.com/show_bug.cgi?id=1215945
* https://bugzilla.suse.com/show_bug.cgi?id=1219494
* https://bugzilla.suse.com/show_bug.cgi?id=1229338
* https://bugzilla.suse.com/show_bug.cgi?id=1230983
* https://bugzilla.suse.com/show_bug.cgi?id=1234028
*...
Read the Full AdvisoryGet the latest Linux and open source security news straight to your inbox.