SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2024-1580

An integer overflow in dav1d AV1 decoder that can occur when decoding videos with large frame size.

HIGH 8.8EPSS 1.84%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.84%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

An integer overflow in dav1d AV1 decoder that can occur when decoding videos with large frame size. This can lead to memory corruption within the AV1 decoder. We recommend upgrading past version 1.4.0 of dav1d.

CVSS 3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
1.84% probability · 78th percentile
CISA KEV
Not listed
Weakness
CWE-190
Affected
videolan/dav1d · apple/safari · apple/ipados · apple/iphone os · apple/macos · apple/visionos · fedoraproject/fedora
Source
cve-coordination@google.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.