Headline
CVE-2020-36329: use-after-free in EmitFancyRGB() in dec/io_dec.c
A flaw was found in libwebp in versions before 1.0.1. A use-after-free was found due to a thread being killed too early. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Description Guilherme de Almeida Suckevicz 2021-05-04 14:18:22 UTC
An use-after-free was found in libwebp in versions before 1.0.1 in EmitFancyRGB() in dec/io_dec.c.
Reference: https://bugs.chromium.org/p/webp/issues/detail?id=385
Comment 1 Riccardo Schirone 2021-05-13 10:55:14 UTC
Upstream patch: https://chromium.googlesource.com/webm/libwebp/+/569001f19fc81fcb5ab358f587a54c62e7c4665c
Comment 4 Riccardo Schirone 2021-05-17 10:47:46 UTC
Upstream release notes: https://chromium.googlesource.com/webm/libwebp/+/v1.0.1
Comment 9 errata-xmlrpc 2021-06-07 12:18:12 UTC
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2021:2260 https://access.redhat.com/errata/RHSA-2021:2260
Comment 10 Product Security DevOps Team 2021-06-07 15:04:00 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-36329
Comment 11 errata-xmlrpc 2021-06-08 22:38:17 UTC
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2021:2328 https://access.redhat.com/errata/RHSA-2021:2328
Comment 12 errata-xmlrpc 2021-06-09 00:25:45 UTC
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2021:2354 https://access.redhat.com/errata/RHSA-2021:2354
Comment 13 errata-xmlrpc 2021-06-09 13:32:25 UTC
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8.1 Extended Update Support
Via RHSA-2021:2365 https://access.redhat.com/errata/RHSA-2021:2365
Comment 14 errata-xmlrpc 2021-06-09 13:51:01 UTC
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8.2 Extended Update Support
Via RHSA-2021:2364 https://access.redhat.com/errata/RHSA-2021:2364