An issue was discovered in GNU libcdio before 2.0.0. There is a double free in getcdtextgeneric() in lib/driver/cdiogeneric.c.
{ "availability": "No subscription required", "binaries": [ { "binary_name": "libcdio-dev", "binary_version": "2.0.0-2" }, { "binary_name": "libcdio-utils", "binary_version": "2.0.0-2" }, { "binary_name": "libcdio-utils-dbgsym", "binary_version": "2.0.0-2" }, { "binary_name": "libcdio18", "binary_version": "2.0.0-2" }, { "binary_name": "libcdio18-dbgsym", "binary_version": "2.0.0-2" }, { "binary_name": "libiso9660-11", "binary_version": "2.0.0-2" }, { "binary_name": "libiso9660-11-dbgsym", "binary_version": "2.0.0-2" }, { "binary_name": "libiso9660-dev", "binary_version": "2.0.0-2" }, { "binary_name": "libudf-dev", "binary_version": "2.0.0-2" }, { "binary_name": "libudf0", "binary_version": "2.0.0-2" }, { "binary_name": "libudf0-dbgsym", "binary_version": "2.0.0-2" } ] }