First published: Wed May 10 2023(Updated: )
VideoLAN dav1d before 1.2.0 has a thread_task.c race condition that can lead to an application crash, related to dav1d_decode_frame_exit.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
VideoLAN dav1d | <1.2.0 | |
Fedoraproject Fedora | =37 | |
Fedoraproject Fedora | =38 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-32570 is a vulnerability in VideoLAN dav1d before version 1.2.0 that can lead to an application crash due to a race condition in thread_task.c.
The severity of CVE-2023-32570 is medium with a CVSS score of 5.9.
If you are using VideoLAN dav1d version before 1.2.0, this vulnerability can potentially cause an application crash.
To fix CVE-2023-32570, you should update VideoLAN dav1d to version 1.2.0 or later.
You can find more information about CVE-2023-32570 in the referenced links: [link1](https://code.videolan.org/videolan/dav1d/-/commit/cf617fdae0b9bfabd27282854c8e81450d955efa), [link2](https://code.videolan.org/videolan/dav1d/-/tags/1.2.0), [link3](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3WGSO7UMOF4MVLQ5H6KIV7OG6ONS377B/).