Bug 34346 - libvpx new security issue CVE-2025-5283
Summary: libvpx new security issue CVE-2025-5283
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA9-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2025-06-04 15:44 CEST by Nicolas Salguero
Modified: 2025-11-07 02:55 CET (History)
4 users (show)

See Also:
Source RPM: libvpx-1.12.0-1.3.mga9.src.rpm
CVE: CVE-2025-5283
Status comment:


Attachments

Nicolas Salguero 2025-06-04 15:45:34 CEST

CVE: (none) => CVE-2025-5283
Source RPM: (none) => libvpx-1.15.0-1.mga10.src.rpm, libvpx-1.12.0-1.3.mga9.src.rpm
Whiteboard: (none) => MGA9TOO
Status comment: (none) => Patch available from upstream and Ubuntu

Comment 1 Marja Van Waes 2025-06-05 20:40:37 CEST
No registered maintainer, so assigning to all.

CC: (none) => marja11
Assignee: bugsquad => pkg-bugs

Comment 3 Nicolas Salguero 2025-10-31 11:16:10 CET
Suggested advisory:
========================

The updated packages fix a security vulnerability:

Double-free in libvpx encoder. (CVE-2025-5283)

References:
https://ubuntu.com/security/notices/USN-7551-1
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KFW4D73K3AUKLCFQCO3CMQVM3FH6SE6V/
========================

Updated packages in core/updates_testing:
========================
lib(64)vpx-devel-1.12.0-1.4.mga9
lib(64)vpx7-1.12.0-1.4.mga9
libvpx-utils-1.12.0-1.4.mga9

from SRPM:
libvpx-1.12.0-1.4.mga9.src.rpm

Version: Cauldron => 9
Assignee: pkg-bugs => qa-bugs
Status comment: Patch available from upstream and Ubuntu => (none)
Source RPM: libvpx-1.15.0-1.mga10.src.rpm, libvpx-1.12.0-1.3.mga9.src.rpm => libvpx-1.12.0-1.3.mga9.src.rpm
Status: NEW => ASSIGNED
Whiteboard: MGA9TOO => (none)

katnatek 2025-10-31 18:34:23 CET

Keywords: (none) => advisory

Comment 4 katnatek 2025-11-04 20:33:49 CET
installing lib64vpx7-1.12.0-1.4.mga9.x86_64.rpm from //home/katnatek/qa-testing/x86_64
Preparing...                     ####################################################################################################
      1/1: lib64vpx7             ####################################################################################################
      1/1: removing lib64vpx7-1.12.0-1.3.mga9.x86_64
                                 ####################################################################################################

Play a webm video with vp9 codec

strace mplayer video.webm shows
openat(AT_FDCWD, "/usr/lib64/libvpx.so.7", O_RDONLY|O_CLOEXEC) = 3

As the bug is in the encoder, I later test with handbrake if no body do it
Comment 5 Herman Viaene 2025-11-05 00:15:49 CET
MGA9-64 server Plasma Wayland on Compaq H000SB.
No installation issues.
Unfortunately for me, previous updates gave me very little specific info on how tests had been done, so started experimenting around with the commands, handicapped by not much detailed knowledge on video formats.
So I ended up using an avi file of my own making, being 4.2 Gb.
$ vpxenc -w 720 -h 576 -o ars.mkv arsmusica1.avi 
Pass 1/2 frame 7237/7238 1505504B    1664b/f   49926b/s  648390 ms (11.16 fps)
Pass 2/2 frame 7237/7213 110277076B 128800674 ms 3.37 fpm [ETA  0:07:12]   13459F  12564F  13590F  14048F    167F  28616F  13239F  13300F  13337F  13Pass 2/2 frame 7237/7237 110593834B  122253b/f 3667613b/s 128558217 ms (0.06 fps)
The first pass took some 15 min. the second pass some +30 HOURS to complete and the result was a 105.5 Mb file, which I cpumd open with vlc, but just showed a 4 min. long display of shimmering colors.
Giving up unless somone can point me to a better use of such command.

CC: (none) => herman.viaene

Comment 6 katnatek 2025-11-06 03:18:01 CET
Convert with handbrake a mp4 video to mkv with vo9 codec the result looks good

Whiteboard: (none) => MGA9-64-OK

Comment 7 Thomas Andrews 2025-11-06 23:53:16 CET
Validating.

Keywords: (none) => validated_update
CC: (none) => andrewsfarm, sysadmin-bugs

Comment 8 Mageia Robot 2025-11-07 02:55:56 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2025-0266.html

Resolution: (none) => FIXED
Status: ASSIGNED => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.