Intel-mediasdk package found in cflinuxfs4
search cancel

Intel-mediasdk package found in cflinuxfs4

book

Article ID: 403158

calendar_today

Updated On:

Products

VMware Tanzu Application Service

Issue/Introduction

Intel-mediasdk package is found within the cflinuxfs4 (bionic) stack in Cloud Foundry.

According to the ubuntu security webpage:

"Intel has issued a Product Discontinuation notice for IntelĀ® Media SDK software and recommends that users of the IntelĀ® Media SDK software uninstall it or discontinue use at their earliest convenience."

The following CVE's that will never have a fix provided by Intel - CVE-2023-22656, CVE-2023-45221, CVE-2023-47169, CVE-2023-47282, CVE-2023-48368

Resolution

The cfllinuxfs4 stack does not directly install in the intel-mediasdk package. It is pulled in through libavcodec58 and is a transitive property of ffmpeg libraries. Intel-mediasdk cannot be removed without also impacting other dependencies which may be used by applications. Tanzu engineering has evaluated removal of Intel-mediasdk but deemed it unsafe to do so.

Eventually cflinuxfs5 will get an updated version of libavcodec58 with the removed package. The recommendation is to wait for this discontinued package to get phased out in the next major stack version - cflinuxfs5 (Noble).