A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version 1.2.18, as used in WhatsApp for Android before version 2.19.244 and many other Android applications, allows remote attackers to execute arbitrary code or cause a denial of service when the library is used to parse a specially crafted GIF image.
{
"unresolved_ranges": [
{
"extracted_events": [
{
"fixed": "2.19.244"
}
],
"cpes": [
"cpe:2.3:a:whatsapp:whatsapp:*:*:*:*:*:android:*:*"
],
"source": "CPE_RANGE",
"vendor_product": "whatsapp:whatsapp"
}
]
}{
"cpe": "cpe:2.3:a:android-gif-drawable_project:android-gif-drawable:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "1.2.18"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}"2026-07-08T15:55:08Z"
[
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"307494684151968822352496849915942941334",
"179646405047686153803200246891620737399",
"3565184496671623564557538637471165139",
"319716975894053961623641977136312660817",
"247672870486026284567417504325281799838",
"231133232878314181211603384170963396143"
]
},
"signature_version": "v1",
"source": "https://github.com/koral--/android-gif-drawable/commit/cc5b4f8e43463995a84efd594f89a21f906c2d20",
"id": "CVE-2019-11932-20c00734",
"target": {
"file": "android-gif-drawable/src/main/c/decoding.c"
}
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 3101.0,
"function_hash": "256783787093088157937719302303409991667"
},
"signature_version": "v1",
"source": "https://github.com/koral--/android-gif-drawable/commit/cc5b4f8e43463995a84efd594f89a21f906c2d20",
"id": "CVE-2019-11932-e657e0c4",
"target": {
"function": "DDGifSlurp",
"file": "android-gif-drawable/src/main/c/decoding.c"
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-11932.json"