VulnerabilityModified
CVE-2024-1580
An integer overflow in dav1d AV1 decoder that can occur when decoding videos with large frame size.
HIGH 8.8EPSS 1.84%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.84%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An integer overflow in dav1d AV1 decoder that can occur when decoding videos with large frame size. This can lead to memory corruption within the AV1 decoder. We recommend upgrading past version 1.4.0 of dav1d.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.84% probability · 78th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-190
- Affected
- videolan/dav1d · apple/safari · apple/ipados · apple/iphone os · apple/macos · apple/visionos · fedoraproject/fedora
- Source
- cve-coordination@google.com
References
- http://seclists.org/fulldisclosure/2024/Mar/36Mailing List
- http://seclists.org/fulldisclosure/2024/Mar/37Mailing List
- http://seclists.org/fulldisclosure/2024/Mar/38Mailing List
- http://seclists.org/fulldisclosure/2024/Mar/39Mailing List
- http://seclists.org/fulldisclosure/2024/Mar/40Mailing List
- http://seclists.org/fulldisclosure/2024/Mar/41Mailing List
- https://code.videolan.org/videolan/dav1d/-/blob/master/NEWSRelease Notes
- https://code.videolan.org/videolan/dav1d/-/releases/1.4.0Release Notes
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5EPMUNDMEBGESOJ2ZNCWYEAYOOEKNWOO/Mailing List
- https://support.apple.com/kb/HT214093Third Party Advisory
- https://support.apple.com/kb/HT214094Third Party Advisory
- https://support.apple.com/kb/HT214095Third Party Advisory
- https://support.apple.com/kb/HT214096Third Party Advisory
- https://support.apple.com/kb/HT214097Third Party Advisory
- https://support.apple.com/kb/HT214098Third Party Advisory
- http://seclists.org/fulldisclosure/2024/Mar/36Mailing List
- http://seclists.org/fulldisclosure/2024/Mar/37Mailing List
- http://seclists.org/fulldisclosure/2024/Mar/38Mailing List
- http://seclists.org/fulldisclosure/2024/Mar/39Mailing List
- http://seclists.org/fulldisclosure/2024/Mar/40Mailing List
- http://seclists.org/fulldisclosure/2024/Mar/41Mailing List
- https://code.videolan.org/videolan/dav1d/-/blob/master/NEWSRelease Notes
- https://code.videolan.org/videolan/dav1d/-/releases/1.4.0Release Notes
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5EPMUNDMEBGESOJ2ZNCWYEAYOOEKNWOO/Mailing List
- https://support.apple.com/kb/HT214093Third Party Advisory
- https://support.apple.com/kb/HT214094Third Party Advisory
- https://support.apple.com/kb/HT214095Third Party Advisory
- https://support.apple.com/kb/HT214096Third Party Advisory
- https://support.apple.com/kb/HT214097Third Party Advisory
- https://support.apple.com/kb/HT214098Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.