CVE-2023-6879

Increasing the resolution of video frames, while performing a multi-threaded encode, can result in a heap overflow in av1_loop_restoration_dealloc().
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9 CRITICAL
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 35%
Affected Products (NVD)
VendorProductVersion
aomediaaomedia
𝑥
< 3.7.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
aom
bookworm
no-dsa
bookworm (security)
vulnerable
bullseye
no-dsa
bullseye (security)
vulnerable
buster
postponed
sid
3.11.0-1
fixed
trixie
3.11.0-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
aom
bionic
ignored
focal
needs-triage
jammy
needs-triage
lunar
ignored
mantic
ignored
noble
not-affected
oracular
not-affected
trusty
ignored
xenial
ignored
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
aom-tools
suse enterprise desktop 15 SP5
3.7.1-150400.3.9.1
fixed
suse enterprise sap 15 SP5
3.7.1-150400.3.9.1
fixed
suse enterprise server 15 SP4
3.7.1-150400.3.9.1
fixed
suse enterprise server 15 SP5
3.7.1-150400.3.9.1
fixed
libaom-devel
suse enterprise desktop 15 SP5
3.7.1-150400.3.9.1
fixed
suse enterprise sap 15 SP5
3.7.1-150400.3.9.1
fixed
suse enterprise server 15 SP4
3.7.1-150400.3.9.1
fixed
suse enterprise server 15 SP5
3.7.1-150400.3.9.1
fixed
libaom-devel-doc
suse enterprise desktop 15 SP5
3.7.1-150400.3.9.1
fixed
suse enterprise sap 15 SP5
3.7.1-150400.3.9.1
fixed
suse enterprise server 15 SP4
3.7.1-150400.3.9.1
fixed
suse enterprise server 15 SP5
3.7.1-150400.3.9.1
fixed
libaom3
suse enterprise desktop 15 SP5
3.7.1-150400.3.9.1
fixed
suse enterprise sap 15 SP5
3.7.1-150400.3.9.1
fixed
suse enterprise server 15 SP4
3.7.1-150400.3.9.1
fixed
suse enterprise server 15 SP5
3.7.1-150400.3.9.1
fixed
libyuv-devel-20230517+a377993
suse enterprise desktop 15 SP5
150400.9.3.1
fixed
suse enterprise sap 15 SP5
150400.9.3.1
fixed
suse enterprise server 15 SP4
150400.9.3.1
fixed
suse enterprise server 15 SP5
150400.9.3.1
fixed
libyuv-tools-20230517+a377993
suse enterprise desktop 15 SP5
150400.9.3.1
fixed
suse enterprise sap 15 SP5
150400.9.3.1
fixed
suse enterprise server 15 SP4
150400.9.3.1
fixed
suse enterprise server 15 SP5
150400.9.3.1
fixed
libyuv0-20230517+a377993
suse enterprise desktop 15 SP5
150400.9.3.1
fixed
suse enterprise sap 15 SP5
150400.9.3.1
fixed
suse enterprise server 15 SP4
150400.9.3.1
fixed
suse enterprise server 15 SP5
150400.9.3.1
fixed