An integer overflow in dav1d AV1 decoder that can occur when decoding videos with large frame size. This can lead to memory corruption within the AV1 decoder. We recommend upgrading past version 1.4.0 of dav1d.
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade dav1d | Mar 26, 2024 | Feb 19, 2024 |
| Apple Osx Coremedia | — | Upgrade macOS to the latest version | Jun 25, 2026 | Mar 25, 2024 |
| Apple Osx Webrtc | — | Upgrade macOS to the latest version | Jun 25, 2026 | Mar 25, 2024 |
| Apple Safari | — | Upgrade to Apple Safari version 17.4.1Uninstall Apple Safari on Windows | Mar 26, 2024 | Feb 19, 2024 |
| Debian | — | Upgrade dav1d | May 13, 2024 | Feb 19, 2024 |
| Freebsd | — | Upgrade electron29Upgrade electron28Upgrade electron27 | Dec 10, 2025 | Apr 18, 2024 |
| Suse | — | Upgrade dav1d-develUpgrade libdav1d7Upgrade dav1dUpgrade libdav1d5Upgrade libdav1d6-32bitUpgrade libdav1d6 | Mar 22, 2024 | Feb 19, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub