Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <b0b2a837-9ed5-48ce-54f0-51f02a58908a@martin.st>
Date: Tue, 19 Aug 2025 10:35:44 +0300 (EEST)
From: Martin Storsjö <martin@...tin.st>
To: Demi Marie Obenour <demiobenour@...il.com>
cc: oss-security@...ts.openwall.com, Sam James <sam@...too.org>, 
    Jordan Glover <Golden_Miller83@...tonmail.ch>
Subject: Re: Question about (in)security of fdk-aac-free in
 linux distros

On Fri, 15 Aug 2025, Demi Marie Obenour wrote:

> What is your recommendation to distro maintainers?  My understanding is
> that the full codec is included in the flathub runtimes but am not sure.

Not sure about what to recommend. From what has been shared, fdk-aac-free 
does indeed seem insecure and/or hard to maintain.

If someone has time to invest in it, it could be fixable by trying to 
recreate the transformation from fdk-aac to fdk-aac-free in the form of a 
small patchset that can be rebased, or a script, ripping out the unwanted 
parts. Unfortunately, going forward with newer versions of fdk-aac, there 
can be more new algorithms that also may need to be patched out (there was 
a pretty big dump of new stuff a number of years ago), so it probably 
needs to be re-audited wrt patents after major updates.

// Martin

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.