VOOZH about

URL: https://www.phoronix.com/news/Fedora-OpenH264-Security-Woe

⇱ Out-Of-Date OpenH264 On Fedora Is Frustrating Users With A High Severity CVE - Phoronix


👁 Phoronix

Out-Of-Date OpenH264 On Fedora Is Frustrating Users With A High Severity CVE

Written by Michael Larabel in Fedora on 29 May 2025 at 08:10 AM EDT. 98 Comments
While OpenH264 support coming to Fedora was widely celebrated as part of offering a better codec experience on Fedora Linux, an increasing number of Fedora users have grown frustrated with the OpenH264 packaging in that it's been out-of-date for several months with a high severity security vulnerability.

The security issue for Cisco's OpenH264 is this vulnerability ranked as a high severity with a score of 8.6 out of 10. The issue stems from the decoding functions of the OpenH264 codec library could allow a remote, unauthenticated attacker to trigger a heap overflow on the system. The CVE was made public in February and fixed by OpenH264 v2.6.

The problem is now three months later Fedora users are still relying on affected versions of OpenH264. Leading to delays in shipping a fixed version of OpenH264 were initially some ABI compatibility concerns and then issues in getting the updated OpenH264 packages into the Cisco-hosted repository. From my external monitoring and receiving reports from various readers frustrated by the problem, getting the updated RPMs to Cisco and into their repository still seem to be a problem. There's also been communication issues with Cisco engineers at times.

The issue can be tracked via this Pagure.io ticket with Fedora release engineering. At the moment the current status is they are still waiting for Cisco on updates.

👁 OpenH264 Fedora package


Having this high severity issue persist for months and given the pervasiveness of H.264 content on the web, there's been some such as on the Fedora development list that have expressed a desire to see the OpenH264 packages removed if they cannot be properly maintained.

In any event hopefully this OpenH264 snafu will be resolved soon.

Michael Larabel is the principal author of Phoronix.com and founded the site in 2004 with a focus on enriching the Linux hardware experience. Michael has written more than 20,000 articles covering the state of Linux hardware support, Linux performance, graphics drivers, and other topics. Michael is also the lead developer of the Phoronix Test Suite, Phoromatic, and OpenBenchmarking.org automated benchmarking software. He can be followed via Twitter, LinkedIn, or contacted via MichaelLarabel.com.