HistoryEditJSON (OSV)

RUSTSEC-2024-0016

dav1d AV1 decoder integer overflow

Reported
Issued
Package
libdav1d-sys (crates.io)
Type
Vulnerability
Categories
Keywords
#integer-overflow
Aliases
References
Patched
  • >=0.7.0

Description

An integer overflow in dav1d AV1 decoder that can occur when decoding videos with large frame size. This can lead to memory corruption within the AV1 decoder. We recommend upgrading to version 0.7.0 of libdav1d-sys, which includes dav1d 1.4.0

Advisory available under CC0-1.0 license.