CVE-2024-1580 Affecting libdav1d6 package, versions <1.0.0-150500.3.6.1


Severity

Recommended
0.0
medium
0
10

Based on SUSE Linux Enterprise Server security rating.

Threat Intelligence

EPSS
0.05% (20th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-SLES155-LIBDAV1D6-6481722
  • published23 Mar 2024
  • disclosed21 Mar 2024

Introduced: 21 Mar 2024

CVE-2024-1580  (opens in a new tab)

How to fix?

Upgrade SLES:15.5 libdav1d6 to version 1.0.0-150500.3.6.1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream libdav1d6 package and not the libdav1d6 package as distributed by SLES. See How to fix? for SLES:15.5 relevant fixed versions and status.

An integer overflow in dav1d AV1 decoder that can occur when decoding videos with large frame size. This can lead to memory corruption within the AV1 decoder. We recommend upgrading past version 1.4.0 of dav1d.

CVSS Scores

version 3.1