An out-of-bounds read was discovered in OpenCV before 4.1.1. Specifically, variable coarsest_scale is assumed to be greater than or equal to finest_scale within the calc()/ocl_calc() functions in dis_flow.cpp. However, this is not true when dealing with small images, leading to an out-of-bounds read of the heap-allocated arrays Ux and Uy.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade opencv | Jul 30, 2024 | Dec 6, 2019 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Dec 6, 2019 |
| Ubuntu | — | Upgrade libopencv-imgcodecs4.5d (Ubuntu Pro)Upgrade libopencv-core4.5d (Ubuntu Pro)Upgrade libopencv-core3.2 (Ubuntu Pro)Upgrade libopencv-contrib4.5d (Ubuntu Pro)Upgrade libopencv-dev (Ubuntu Pro)Upgrade libopencv-flann4.5d (Ubuntu Pro)Upgrade libopencv-objdetect4.5d (Ubuntu Pro)Upgrade opencv-data (Ubuntu Pro)Upgrade libopencv-dnn4.5d (Ubuntu Pro) | Feb 4, 2025 | Dec 6, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub