CVE-2024-1580

Published Feb 19, 2024

Last updated 10 days ago

Overview

Description
An integer overflow in dav1d AV1 decoder that can occur when decoding videos with large frame size. This can lead to memory corruption within the AV1 decoder. We recommend upgrading past version 1.4.0 of dav1d.
Source
cve-coordination@google.com
NVD status
Modified

Risk scores

CVSS 3.1

Type
Primary
Base score
8.8
Impact score
5.9
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

cve-coordination@google.com
CWE-190
nvd@nist.gov
CWE-190

Social media

Hype score
Not currently trending

Configurations

References