CVE-2022-48363
7.5HIGHIn MPD before 0.23.8, as used on Automotive Grade Linux and other platforms, the PipeWire output plugin mishandles a Drain call in certain situations involving truncated files. Eventually there is an
Published: 2/26/2023Updated: 3/11/2025
Description
In MPD before 0.23.8, as used on Automotive Grade Linux and other platforms, the PipeWire output plugin mishandles a Drain call in certain situations involving truncated files. Eventually there is an assertion failure in libmpdclient because libqtappfw passes in a NULL pointer.
AI AnalysisPowered by AI
Affected Products
linuxfoundationautomotive_grade_linux
References
- https://gerrit.automotivelinux.org/gerrit/c/src/libqtappfw/+/28484Patch
- https://gerrit.automotivelinux.org/gerrit/c/src/libqtappfw/+/28485Patch
- https://gerrit.automotivelinux.org/gerrit/q/project:src%252Flibqtappfw+status:openNot Applicable
- https://jira.automotivelinux.org/browse/SPEC-4661Exploit
- https://gerrit.automotivelinux.org/gerrit/c/src/libqtappfw/+/28484Patch
- https://gerrit.automotivelinux.org/gerrit/c/src/libqtappfw/+/28485Patch
- https://gerrit.automotivelinux.org/gerrit/q/project:src%252Flibqtappfw+status:openNot Applicable
- https://jira.automotivelinux.org/browse/SPEC-4661Exploit