oss-sec mailing list archives
Re: Question about (in)security of fdk-aac-free in linux distros
From: Martin Storsjö <martin () martin st>
Date: Tue, 19 Aug 2025 10:35:44 +0300 (EEST)
On Fri, 15 Aug 2025, Demi Marie Obenour wrote:
What is your recommendation to distro maintainers? My understanding is that the full codec is included in the flathub runtimes but am not sure.
Not sure about what to recommend. From what has been shared, fdk-aac-free does indeed seem insecure and/or hard to maintain.
If someone has time to invest in it, it could be fixable by trying to recreate the transformation from fdk-aac to fdk-aac-free in the form of a small patchset that can be rebased, or a script, ripping out the unwanted parts. Unfortunately, going forward with newer versions of fdk-aac, there can be more new algorithms that also may need to be patched out (there was a pretty big dump of new stuff a number of years ago), so it probably needs to be re-audited wrt patents after major updates.
// Martin
Current thread:
- Question about (in)security of fdk-aac-free in linux distros Jordan Glover (Aug 13)
- Re: Question about (in)security of fdk-aac-free in linux distros Sam James (Aug 14)
- Re: Question about (in)security of fdk-aac-free in linux distros Martin Storsjö (Aug 14)
- Re: Question about (in)security of fdk-aac-free in linux distros Demi Marie Obenour (Aug 15)
- Re: Question about (in)security of fdk-aac-free in linux distros Jordan Glover (Aug 15)
- Re: Question about (in)security of fdk-aac-free in linux distros Martin Storsjö (Aug 19)
- Re: Question about (in)security of fdk-aac-free in linux distros Demi Marie Obenour (Aug 19)
- Re: Question about (in)security of fdk-aac-free in linux distros Martin Storsjö (Aug 14)
- Re: Question about (in)security of fdk-aac-free in linux distros Sam James (Aug 14)
