CVE-2022-48363
7.5HIGHIn MPD before 0.23.8, as used on Automotive Grade Linux and other platforms, the PipeWire output plugin mishandles a Drain call in certain situations involving truncated files. Eventually there is an
Veröffentlicht: 2/26/2023Aktualisiert: 3/11/2025
Beschreibung
In MPD before 0.23.8, as used on Automotive Grade Linux and other platforms, the PipeWire output plugin mishandles a Drain call in certain situations involving truncated files. Eventually there is an assertion failure in libmpdclient because libqtappfw passes in a NULL pointer.
KI-AnalyseKI-gestützt
Betroffene Produkte
linuxfoundationautomotive_grade_linux
Referenzen
- https://gerrit.automotivelinux.org/gerrit/c/src/libqtappfw/+/28484Patch
- https://gerrit.automotivelinux.org/gerrit/c/src/libqtappfw/+/28485Patch
- https://gerrit.automotivelinux.org/gerrit/q/project:src%252Flibqtappfw+status:openNot Applicable
- https://jira.automotivelinux.org/browse/SPEC-4661Exploit
- https://gerrit.automotivelinux.org/gerrit/c/src/libqtappfw/+/28484Patch
- https://gerrit.automotivelinux.org/gerrit/c/src/libqtappfw/+/28485Patch
- https://gerrit.automotivelinux.org/gerrit/q/project:src%252Flibqtappfw+status:openNot Applicable
- https://jira.automotivelinux.org/browse/SPEC-4661Exploit