FFmpeg version n6.1.1 has a double-free vulnerability in the fftools/ffmpegmuxinit.c component of FFmpeg, specifically within the newstreamaudio function.
{ "vanir_signatures": [ { "digest": { "line_hashes": [ "249820132623253543553490728674137305401", "16771152866182400697910379174276812168", "268309704837510785664467086767804070601", "139329774877160731337824940128499674296", "146236428504916513888329669483663052147", "200123169525105980865852167512660543544", "120084957814246726962187685865891787540", "65640019006969470111446989074590513816", "209321188422532355042386325062983715705" ], "threshold": 0.9 }, "target": { "file": "fftools/ffmpeg_mux_init.c" }, "signature_type": "Line", "source": "https://github.com/ffmpeg/ffmpeg/commit/ced5c5fdb8634d39ca9472a2026b2d2fea16c4e5", "deprecated": false, "signature_version": "v1", "id": "CVE-2024-35365-d7e17482" }, { "digest": { "length": 1045.0, "function_hash": "194879047104013296996807666164536683106" }, "target": { "function": "new_stream_audio", "file": "fftools/ffmpeg_mux_init.c" }, "signature_type": "Function", "source": "https://github.com/ffmpeg/ffmpeg/commit/ced5c5fdb8634d39ca9472a2026b2d2fea16c4e5", "deprecated": false, "signature_version": "v1", "id": "CVE-2024-35365-d813b04b" } ] }