CVE-2024-1580

An integer overflow in dav1d AV1 decoder that can occur when decoding videos with large frame size. This can lead to memory corruption within the AV1 decoder. We recommend upgrading past version 1.4.0 of dav1d.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.9 MEDIUM
ADJACENT_NETWORK
HIGH
LOW
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:L
GoogleCNA
5.9 MEDIUM
ADJACENT_NETWORK
HIGH
LOW
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:L
CISA-ADPADP
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 44%
VendorProductVersion
videolandav1d
𝑥
< 1.4.0
applesafari
𝑥
< 17.4.1
appleipados
𝑥
< 16.7.7
appleipados
17.0 ≤
𝑥
< 17.4.1
appleiphone_os
𝑥
< 16.7.7
appleiphone_os
17.0 ≤
𝑥
< 17.4.1
applemacos
13.0 ≤
𝑥
< 13.6.6
applemacos
14.0 ≤
𝑥
< 14.4.1
applevisionos
𝑥
< 1.1.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
dav1d
bullseye (security)
0.7.1-3+deb11u1
fixed
bullseye
0.7.1-3+deb11u1
fixed
bookworm
1.0.0-2+deb12u1
fixed
bookworm (security)
1.0.0-2+deb12u1
fixed
sid
1.5.1-1
fixed
trixie
1.5.1-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
dav1d
plucky
needs-triage
oracular
needs-triage
noble
needs-triage
mantic
ignored
jammy
needs-triage
focal
dne
bionic
dne
xenial
dne
trusty
dne