CVE-2024-1580

MEDIUM

dav1d < 1.4.0 - Integer Overflow in AV1 Decoder

Title source: llm
STIX 2.1

Description

An integer overflow in dav1d AV1 decoder that can occur when decoding videos with large frame size. This can lead to memory corruption within the AV1 decoder. We recommend upgrading past version 1.4.0 of dav1d.

Scores

CVSS v3 5.9
EPSS 0.0058
EPSS Percentile 69.3%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-190
Status published
Products (7)
apple/ipados < 16.7.7
apple/iphone_os < 16.7.7
apple/macos 13.0 - 13.6.6
apple/safari < 17.4.1
apple/visionos < 1.1.1
fedoraproject/fedora 40
videolan/dav1d < 1.4.0
Published Feb 19, 2024
Tracked Since Feb 18, 2026