THREATOPS
THREAT OPSThreat News › Memory-safety defects in the upstream (abandoned) AOSP OpenCORE AAC decoder, shipped unpatched by Samsung TizenRT

Memory-safety defects in the upstream (abandoned) AOSP OpenCORE AAC decoder, shipped unpatched by Samsung TizenRT

lowoss_secPublished 2026-09-10

<p>Posted by Eve on Sep 09</p>Summary<br /> =======<br /> The OpenCORE AAC decoder (AOSP external/opencore, codecs_v2/audio/aac/dec) is abandoned upstream but is still<br /> vendored and built by multiple projects, most notably Samsung&apos;s TizenRT (a widely-deployed embedded RTOS).<br /> It contains memory-safety defects of the out-of-bounds-write and wild-pointer class, reachable from<br /> un

Original source: https://seclists.org/oss-sec/2026/q3/702