In discussions with upstream developers, because we a fixing an older
version than is covered by the patches in the advisory, a slightly
different and expanded patch set is required.

These are:

https://invent.kde.org/multimedia/kdenlive/-/commit/b9173d1401e3c02100ac8681e0e03c57ad9c407c
https://invent.kde.org/multimedia/kdenlive/-/commit/a789bf5d29cc8e578e4d3009badef0fadca62450
https://invent.kde.org/multimedia/kdenlive/-/commit/94042ddd259551e4a7a5f6672329752972c84685

as applied to the 25.12 upstream branch

This patch: 
https://invent.kde.org/multimedia/kdenlive/-/commit/d71159d9af14674a0d373a135f0a7f0ec01eb060
was also requested, but turned out to be too onerous to backport to that branch.

However, the issue d71159d9af can be nullified by applying this patch to MLT in 
the Ubuntu archive.
https://github.com/mltframework/mlt/commit/4f2bb3b804d9cdb0018c723315df930932f1d0dd

This I will do in a separate bug, or will combine with this one if
security prefer it that way.

** CVE added: https://cve.org/CVERecord?id=CVE-2026-45184

** Changed in: kdenlive (Ubuntu)
       Status: New => Confirmed

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2168441

Title:
   Kdenlive: Remote code execution via malicious project file

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/kdenlive/+bug/2168441/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to