An issue was discovered in the FFmpeg package, where vp3decodeframe in libavcodec/vp3.c lacks check of the return value of av_malloc() and will cause a null pointer dereference, impacting availability.
{
"unresolved_ranges": [
{
"cpe": "cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*",
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "10.0"
}
]
},
{
"cpe": "cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*",
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "11.0"
}
]
},
{
"cpe": "cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*",
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "36"
}
]
}
]
}{
"cpe": "cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*",
"source": [
"CPE_FIELD",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "5.0.3"
}
]
}"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-3109.json"
"2026-04-12T04:42:48Z"
[
{
"signature_type": "Line",
"id": "CVE-2022-3109-2009719d",
"source": "https://github.com/ffmpeg/ffmpeg/commit/656cb0450aeb73b25d7d26980af342b37ac4c568",
"deprecated": false,
"digest": {
"line_hashes": [
"296668209892502617258083696776298184501",
"179955415149809112259535756720552300062",
"234635089860816423356759960037085279787",
"223938992080501052778109654229955851693",
"114824492263024678544587325202192976403"
],
"threshold": 0.9
},
"target": {
"file": "libavcodec/vp3.c"
},
"signature_version": "v1"
},
{
"signature_type": "Function",
"id": "CVE-2022-3109-6328b518",
"signature_version": "v1",
"deprecated": false,
"digest": {
"function_hash": "227388434592210151558034273051090982660",
"length": 7000.0
},
"target": {
"file": "libavcodec/vp3.c",
"function": "vp3_decode_frame"
},
"source": "https://github.com/ffmpeg/ffmpeg/commit/656cb0450aeb73b25d7d26980af342b37ac4c568"
}
]