What the vulnerability does

01Description

An issue was discovered in the FFmpeg package, where vp3_decode_frame in libavcodec/vp3.c lacks check of the return value of av_malloc() and will cause a null pointer dereference, impacting availability.

Key dates

02Disclosure timeline

December 16, 2022 CVE published
April 16, 2025 Record updated