Use-after-free in Simple DirectMedia Layer - CVE-2022-34568
Published: August 30, 2022
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a use-after-free error within the XFree() function in video/x11/SDL_x11yuv.c. A remote attacker can pass specially crafted input to the library, trigger a use-after-free error and perform a denial of service (DoS) attack.
Affected software
Gentoo Linux
Ubuntu
libsdl1.2debian (Ubuntu package)
How to mitigate CVE-2022-34568
libsdl1.2debian (Ubuntu package) - update to 1.2.15+dfsg13ubuntu0.1+esm2