Medium severity5.9NVD Advisory· Published Feb 19, 2024· Updated Jun 17, 2026
CVE-2024-1580
CVE-2024-1580
Description
An integer overflow in dav1d AV1 decoder that can occur when decoding videos with large frame size. This can lead to memory corruption within the AV1 decoder. We recommend upgrading past version 1.4.0 of dav1d.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
13- cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:*
- osv-coords4 versionspkg:rpm/opensuse/dav1d&distro=openSUSE%20Leap%2015.5pkg:rpm/suse/dav1d&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP5pkg:rpm/suse/dav1d&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP5pkg:rpm/suse/dav1d&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP5
< 1.0.0-150500.3.6.1+ 3 more
- (no CPE)range: < 1.0.0-150500.3.6.1
- (no CPE)range: < 0.9.2-150400.3.3.1
- (no CPE)range: < 1.0.0-150500.3.6.1
- (no CPE)range: < 1.0.0-150500.3.6.1
Patches
Vulnerability mechanics
References
15- support.apple.com/kb/HT214093nvdThird Party Advisory
- support.apple.com/kb/HT214094nvdThird Party Advisory
- support.apple.com/kb/HT214095nvdThird Party Advisory
- support.apple.com/kb/HT214096nvdThird Party Advisory
- support.apple.com/kb/HT214097nvdThird Party Advisory
- support.apple.com/kb/HT214098nvdThird Party Advisory
- seclists.org/fulldisclosure/2024/Mar/36nvdMailing List
- seclists.org/fulldisclosure/2024/Mar/37nvdMailing List
- seclists.org/fulldisclosure/2024/Mar/38nvdMailing List
- seclists.org/fulldisclosure/2024/Mar/39nvdMailing List
- seclists.org/fulldisclosure/2024/Mar/40nvdMailing List
- seclists.org/fulldisclosure/2024/Mar/41nvdMailing List
- code.videolan.org/videolan/dav1d/-/blob/master/NEWSnvdRelease Notes
- code.videolan.org/videolan/dav1d/-/releases/1.4.0nvdRelease Notes
- lists.fedoraproject.org/archives/list/[email protected]/message/5EPMUNDMEBGESOJ2ZNCWYEAYOOEKNWOO/nvdMailing List
News mentions
0No linked articles in our index yet.