CVE-2024-56431
published 2024-12-25CVE-2024-56431: oc_huff_tree_unpack in huffdec.c in libtheora in Theora through 1.0 7180717 has an invalid negative left shift. NOTE: this is disputed by third parties because…
PriorityP344critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.82%
76.3th percentile
oc_huff_tree_unpack in huffdec.c in libtheora in Theora through 1.0 7180717 has an invalid negative left shift. NOTE: this is disputed by third parties because there is no evidence of a security impact, e.g., an application would not crash.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libtheora | < libtheora 1.2.0~alpha1+dfsg-6 (forky) | libtheora 1.2.0~alpha1+dfsg-6 (forky) |
| xiph | theora | < 1.2.0 | 1.2.0 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_debian9.8LOW
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8xp8-gmmj-xc8w: oc_huff_tree_unpack in huffdec
ghsa_unreviewed·2024-12-25
CVE-2024-56431 [CRITICAL] CWE-863 GHSA-8xp8-gmmj-xc8w: oc_huff_tree_unpack in huffdec
oc_huff_tree_unpack in huffdec.c in libtheora in Theora through 1.0 7180717 has an invalid negative left shift.
OSV
CVE-2024-56431: oc_huff_tree_unpack in huffdec
osv·2024-12-25·CVSS 9.8
CVE-2024-56431 [CRITICAL] CVE-2024-56431: oc_huff_tree_unpack in huffdec
oc_huff_tree_unpack in huffdec.c in libtheora in Theora through 1.0 7180717 has an invalid negative left shift. NOTE: this is disputed by third parties because there is no evidence of a security impact, e.g., an application would not crash.
Red Hat
libtheora: incorrect bitwise shift in huffdec.c
vendor_redhat·2024-12-25·CVSS 9.8
CVE-2024-56431 [CRITICAL] CWE-1335 libtheora: incorrect bitwise shift in huffdec.c
libtheora: incorrect bitwise shift in huffdec.c
oc_huff_tree_unpack in huffdec.c in libtheora in Theora through 1.0 7180717 has an invalid negative left shift. NOTE: this is disputed by third parties because there is no evidence of a security impact, e.g., an application would not crash.
A flaw was found in Theora (libtheora). An incorrect bitwise shift may be triggered via specially-crafted input, potentially resulting in an application crash.
Package: libtheora (Red Hat Enterprise Linux 10) - Fix deferred
Package: libtheora (Red Hat Enterprise Linux 6) - Out of support scope
Package: firefox (Red Hat Enterprise Linux 7) - Out of support scope
Package: libtheora (Red Hat Enterprise Linux 7) - Out of support scope
Package: thunderbird (Red Hat Enterprise Linux 7) - Out of support sc
Debian
CVE-2024-56431: libtheora - oc_huff_tree_unpack in huffdec.c in libtheora in Theora through 1.0 7180717 has ...
vendor_debian·2024·CVSS 9.8
CVE-2024-56431 [CRITICAL] CVE-2024-56431: libtheora - oc_huff_tree_unpack in huffdec.c in libtheora in Theora through 1.0 7180717 has ...
oc_huff_tree_unpack in huffdec.c in libtheora in Theora through 1.0 7180717 has an invalid negative left shift. NOTE: this is disputed by third parties because there is no evidence of a security impact, e.g., an application would not crash.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 1.2.0~alpha1+dfsg-6)
sid: resolved (fixed in 1.2.0~alpha1+dfsg-6)
trixie: resolved (fixed in 1.2.0~alpha1+dfsg-6)
No detection rules found.
No public exploits indexed.
https://github.com/UnionTech-Software/libtheora-CVE-2024-56431-PoChttps://github.com/xiph/theora/blob/7180717276af1ebc7da15c83162d6c5d6203aabf/lib/huffdec.c#L193https://github.com/xiph/theora/issues/17#issuecomment-2480630603https://www.openwall.com/lists/oss-security/2025/04/25/6http://www.openwall.com/lists/oss-security/2025/04/25/4http://www.openwall.com/lists/oss-security/2025/04/25/6
2024-12-25
Published