CVE-2024-31578: Fedoraproject Fedora
High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.
FFmpeg version n6.1.1 was discovered to contain a heap use-after-free via the av_hwframe_ctx_init function.
Affected products
- Fedoraproject Fedora: version 38 only; version 39 only; version 40 only
- Ffmpeg Ffmpeg: before 7.0 (fixed in 7.0)
Published 2024-04-17. Last modified 2026-06-17.