CVE-2023-6879
published 2023-12-27CVE-2023-6879: Increasing the resolution of video frames, while performing a multi-threaded encode, can result in a heap overflow in av1_loop_restoration_dealloc().
PriorityP344critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.17%
64.2th percentile
Increasing the resolution of video frames, while performing a multi-threaded encode, can result in a heap overflow in av1_loop_restoration_dealloc().
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| aomedia | aomedia | < 3.7.1 | 3.7.1 |
| debian | aom | < aom 3.7.1-1 (forky) | aom 3.7.1-1 (forky) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| libaom | libaom | < 3.7.1 | 3.7.1 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_debian9.0CRITICAL
vendor_redhat9.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
libaom up to 3.7.0 Multi-Thread av1_loop_restoration_dealloc heap-based overflow (FEDORA-2024-210776b8c7)
vuldb·2026-06-24·CVSS 9.8
CVE-2023-6879 [CRITICAL] libaom up to 3.7.0 Multi-Thread av1_loop_restoration_dealloc heap-based overflow (FEDORA-2024-210776b8c7)
A vulnerability described as critical has been identified in libaom up to 3.7.0. This affects the function av1_loop_restoration_dealloc of the component Multi-Thread Handler. The manipulation results in heap-based buffer overflow.
This vulnerability is cataloged as CVE-2023-6879. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is recommended.
GHSA
GHSA-fvcr-3mhq-rw2x: Increasing the resolution of video frames, while performing a multi-threaded encode, can result in a heap overflow in av1_loop_restoration_dealloc()
ghsa_unreviewed·2023-12-28
CVE-2023-6879 [CRITICAL] CWE-20 GHSA-fvcr-3mhq-rw2x: Increasing the resolution of video frames, while performing a multi-threaded encode, can result in a heap overflow in av1_loop_restoration_dealloc()
Increasing the resolution of video frames, while performing a multi-threaded encode, can result in a heap overflow in av1_loop_restoration_dealloc().
OSV
CVE-2023-6879: Increasing the resolution of video frames, while performing a multi-threaded encode, can result in a heap overflow in av1_loop_restoration_dealloc()
osv·2023-12-27·CVSS 9.8
CVE-2023-6879 [CRITICAL] CVE-2023-6879: Increasing the resolution of video frames, while performing a multi-threaded encode, can result in a heap overflow in av1_loop_restoration_dealloc()
Increasing the resolution of video frames, while performing a multi-threaded encode, can result in a heap overflow in av1_loop_restoration_dealloc().
Red Hat
aom: heap-buffer-overflow on frame size change
vendor_redhat·2023-12-28·CVSS 9.0
CVE-2023-6879 [CRITICAL] CWE-787 aom: heap-buffer-overflow on frame size change
aom: heap-buffer-overflow on frame size change
Increasing the resolution of video frames, while performing a multi-threaded encode, can result in a heap overflow in av1_loop_restoration_dealloc().
A heap-based buffer overflow vulnerability was found in AOM. When increasing the resolution of video frames during a multi-threaded encode, a heap overflow may occur in av1_loop_restoration_dealloc() within thread_common.c, leading to a denial of service or unauthorized reading of memory.
Statement: The AOM heap-based buffer overflow vulnerability, triggered when increasing video frame resolution during a multi-threaded encode, is considered moderate. Limited conditions for exploitation and constrained impacts, such as potential denial of service and unauthorized memory reading, contribute to
Debian
CVE-2023-6879: aom - Increasing the resolution of video frames, while performing a multi-threaded enc...
vendor_debian·2023·CVSS 9.0
CVE-2023-6879 [CRITICAL] CVE-2023-6879: aom - Increasing the resolution of video frames, while performing a multi-threaded enc...
Increasing the resolution of video frames, while performing a multi-threaded encode, can result in a heap overflow in av1_loop_restoration_dealloc().
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 3.7.1-1)
sid: resolved (fixed in 3.7.1-1)
trixie: resolved (fixed in 3.7.1-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://aomedia.googlesource.com/aom/+/refs/tags/v3.7.1https://crbug.com/aomedia/3491https://lists.fedoraproject.org/archives/list/[email protected]/message/AYONA2XSNFMXLAW4IHLFI5UVV3QRNG5K/https://lists.fedoraproject.org/archives/list/[email protected]/message/D6C2HN4T2S6GYNTAUXLH45LQZHK7QPHP/https://aomedia.googlesource.com/aom/+/refs/tags/v3.7.1https://crbug.com/aomedia/3491https://lists.fedoraproject.org/archives/list/[email protected]/message/AYONA2XSNFMXLAW4IHLFI5UVV3QRNG5K/https://lists.fedoraproject.org/archives/list/[email protected]/message/D6C2HN4T2S6GYNTAUXLH45LQZHK7QPHP/
2023-12-27
Published