Description An integer overflow in dav1d AV1 decoder that can occur when decoding videos with large frame size. This can lead to memory corruption within the AV1 decoder. We recommend upgrading past version 1.4.0 of dav1d.
CVSS vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Exploitability: 2.8 | Impact: 5.9 Attack Vector: Network
Complexity: Low
Privileges: Low
User Interaction: None
Scope: Unchanged
Confidentiality: High
Integrity: High
Availability: High
Affected Packages8 packages Show 3 more packages Also affects: Fedora 40
🔴 Vulnerability Details4 Project0 Effective Fuzzing: A Dav1d Case Study - Project Zero ↗ 2024-10-01 ▶ GHSA GHSA-3p7f-4r2q-wxmm: An integer overflow in dav1d AV1 decoder that can occur when decoding videos with large frame size ↗ 2024-02-19 ▶ CVEList Integer overflow in VideoLAN dav1d ↗ 2024-02-19 ▶ OSV CVE-2024-1580: An integer overflow in dav1d AV1 decoder that can occur when decoding videos with large frame size ↗ 2024-02-19 ▶
📋 Vendor Advisories7 Apple CVE-2024-1580: macOS Sonoma 14.4.1 ↗ 2024-03-25 ▶ Apple CVE-2024-1580: Safari 17.4.1 ↗ 2024-03-25 ▶ Apple CVE-2024-1580: macOS Ventura 13.6.6 ↗ 2024-03-25 ▶ Apple CVE-2024-1580: iOS 17.4.1 and iPadOS 17.4.1 ↗ 2024-03-21 ▶ Apple CVE-2024-1580: visionOS 1.1.1 ↗ 2024-03-21 ▶ Show 2 more
💬 Community1 Bugzilla Evaluate dav1d CVE-2024-1580 fix ↗ 2024-02-20 ▶