CVE-2024-1580

EUVD-2024-17324
An integer overflow in dav1d AV1 decoder that can occur when decoding videos with large frame size. This can lead to memory corruption within the AV1 decoder. We recommend upgrading past version 1.4.0 of dav1d.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.9 MEDIUM
ADJACENT_NETWORK
HIGH
LOW
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 69%
Affected Products (NVD)
VendorProductVersion
videolandav1d
𝑥
< 1.4.0
applesafari
𝑥
< 17.4.1
appleipados
𝑥
< 16.7.7
appleipados
17.0 ≤
𝑥
< 17.4.1
appleiphone_os
𝑥
< 16.7.7
appleiphone_os
17.0 ≤
𝑥
< 17.4.1
applemacos
13.0 ≤
𝑥
< 13.6.6
applemacos
14.0 ≤
𝑥
< 14.4.1
applevisionos
𝑥
< 1.1.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
dav1d
bookworm
1.0.0-2+deb12u1
fixed
bookworm (security)
1.0.0-2+deb12u1
fixed
bullseye
0.7.1-3+deb11u1
fixed
bullseye (security)
0.7.1-3+deb11u1
fixed
forky
1.5.2-1
fixed
sid
1.5.2-1
fixed
trixie
1.5.1-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
dav1d
bionic
dne
focal
dne
jammy
needs-triage
mantic
ignored
noble
needs-triage
oracular
ignored
plucky
needs-triage
questing
needs-triage
trusty
dne
xenial
dne
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
dav1d-devel
suse enterprise desktop 15 SP5
1.0.0-150500.3.6.1
fixed
suse enterprise desktop 15 SP6
1.4.0-150600.1.2
fixed
suse enterprise desktop 15 SP7
1.4.0-150600.1.2
fixed
suse enterprise sap 15 SP5
1.0.0-150500.3.6.1
fixed
suse enterprise sap 15 SP6
1.4.0-150600.1.2
fixed
suse enterprise sap 15 SP7
1.4.0-150600.1.2
fixed
suse enterprise server 15 SP5
1.0.0-150500.3.6.1
fixed
suse enterprise server 15 SP6
1.4.0-150600.1.2
fixed
suse enterprise server 15 SP7
1.4.0-150600.1.2
fixed
libdav1d5
suse enterprise desktop 15 SP5
0.9.2-150400.3.3.1
fixed
suse enterprise desktop 15 SP6
0.9.2-150400.3.3.1
fixed
suse enterprise desktop 15 SP7
0.9.2-150400.3.3.1
fixed
suse enterprise sap 15 SP5
0.9.2-150400.3.3.1
fixed
suse enterprise sap 15 SP6
0.9.2-150400.3.3.1
fixed
suse enterprise sap 15 SP7
0.9.2-150400.3.3.1
fixed
suse enterprise server 15 SP5
0.9.2-150400.3.3.1
fixed
suse enterprise server 15 SP6
0.9.2-150400.3.3.1
fixed
suse enterprise server 15 SP7
0.9.2-150400.3.3.1
fixed
libdav1d6
suse enterprise desktop 15 SP5
1.0.0-150500.3.6.1
fixed
suse enterprise sap 15 SP5
1.0.0-150500.3.6.1
fixed
suse enterprise server 15 SP5
1.0.0-150500.3.6.1
fixed
libdav1d7
suse enterprise desktop 15 SP6
1.4.0-150600.1.2
fixed
suse enterprise sap 15 SP6
1.4.0-150600.1.2
fixed
suse enterprise server 15 SP6
1.4.0-150600.1.2
fixed