In discussions with upstream developers, because we a fixing an older version than is covered by the patches in the advisory, a slightly different and expanded patch set is required.
These are: https://invent.kde.org/multimedia/kdenlive/-/commit/b9173d1401e3c02100ac8681e0e03c57ad9c407c https://invent.kde.org/multimedia/kdenlive/-/commit/a789bf5d29cc8e578e4d3009badef0fadca62450 https://invent.kde.org/multimedia/kdenlive/-/commit/94042ddd259551e4a7a5f6672329752972c84685 as applied to the 25.12 upstream branch This patch: https://invent.kde.org/multimedia/kdenlive/-/commit/d71159d9af14674a0d373a135f0a7f0ec01eb060 was also requested, but turned out to be too onerous to backport to that branch. However, the issue d71159d9af can be nullified by applying this patch to MLT in the Ubuntu archive. https://github.com/mltframework/mlt/commit/4f2bb3b804d9cdb0018c723315df930932f1d0dd This I will do in a separate bug, or will combine with this one if security prefer it that way. ** CVE added: https://cve.org/CVERecord?id=CVE-2026-45184 ** Changed in: kdenlive (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2168441 Title: Kdenlive: Remote code execution via malicious project file To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/kdenlive/+bug/2168441/+subscriptions -- ubuntu-bugs mailing list [email protected] https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
