CVE-2023-6350

NameCVE-2023-6350
DescriptionUse after free in libavif in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to potentially exploit heap corruption via a crafted avif file. (Chromium security severity: High)
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-5569-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
chromium (PTS)bullseye (security), bullseye120.0.6099.224-1~deb11u1fixed
bookworm135.0.7049.95-1~deb12u1fixed
bookworm (security)137.0.7151.55-3~deb12u1fixed
trixie136.0.7103.113-1fixed
sid137.0.7151.55-3fixed
libavif (PTS)bullseye0.8.4-2+deb11u1fixed
bullseye (security)0.8.4-2+deb11u2fixed
bookworm0.11.1-1fixed
bookworm (security)0.11.1-1+deb12u1fixed
trixie, sid1.2.1-1.2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
chromiumsourcebuster(unfixed)end-of-life
chromiumsourcebullseye119.0.6045.199-1~deb11u1DSA-5569-1
chromiumsourcebookworm119.0.6045.199-1~deb12u1DSA-5569-1
chromiumsource(unstable)119.0.6045.199-1
libavifsource(unstable)(not affected)

Notes

[buster] - chromium <end-of-life> (see DSA 5046)
- libavif <not-affected> (No Debian released version contained vulnerable code)
https://issues.chromium.org/issues/40942077
Introduced in https://github.com/AOMediaCodec/libavif/commit/c17d24ad2281fee383700e0710e019758a1969ad (v1.0.0)
https://github.com/AOMediaCodec/libavif/pull/1756
https://github.com/AOMediaCodec/libavif/commit/6d62963f74aa76dbe05ac8c84bed94dece9ddde5 (v1.1.0)

Search for package or bug name: Reporting problems