First published: Wed Dec 27 2023(Updated: )
Increasing the resolution of video frames, while performing a multi-threaded encode, can result in a heap overflow in av1_loop_restoration_dealloc().
Credit: cve-coordination@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
AOM | <3.7.1 | |
Fedora | =38 | |
Fedora | =39 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-6879 has been classified as a high-severity vulnerability due to the potential for a heap overflow.
To fix CVE-2023-6879, update the AOMedia software to version 3.7.1 or later, or ensure you are using a patched version on Fedora systems.
CVE-2023-6879 affects AOMedia versions below 3.7.1 and Fedora versions 38 and 39.
Exploitation of CVE-2023-6879 can lead to application crashes and potentially allow remote code execution.
CVE-2023-6879 specifically impacts the av1_loop_restoration_dealloc() function during multi-threaded video frame encoding.