CVE-2023-6879
CRITICALaomedia < 3.7.1 - Heap Overflow via Multi-Threaded Video Frame Resolution Increase
Title source: llmDescription
Increasing the resolution of video frames, while performing a multi-threaded encode, can result in a heap overflow in av1_loop_restoration_dealloc().
References (4)
Core 4
Core References
Exploit, Issue Tracking, Mailing List, Patch, Third Party Advisory
https://crbug.com/aomedia/3491
Mailing List, Third Party Advisory
https://lists.fedoraproject.org/archives/list/[email protected]/message/AYONA2XSNFMXLAW4IHLFI5UVV3QRNG5K/
Mailing List, Third Party Advisory
https://lists.fedoraproject.org/archives/list/[email protected]/message/D6C2HN4T2S6GYNTAUXLH45LQZHK7QPHP/
Scores
CVSS v3
9.0
EPSS
0.0015
EPSS Percentile
35.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Details
CWE
CWE-20
CWE-787
Status
published
Products (3)
aomedia/aomedia
< 3.7.1
fedoraproject/fedora
38
fedoraproject/fedora
39
Published
Dec 27, 2023
Tracked Since
Feb 18, 2026