CVE-2023-6879: heap buffer overflow in libaom
Published Dec 27, 2023
·Updated
Increasing the resolution of video frames, while performing a multi-threaded encode, can result in a heap overflow in av1looprestorationdealloc().
Affected Software
3 affected components
AOMedia AOMedia<3.7.1
Fedoraproject Fedora=38
Fedoraproject Fedora=39
Remediation
Patch Available
Patch Available
Event History
Dec 27, 2023
CVE Published
via MITRE·10:16 PM
Data Sourced
via MITRE·10:16 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-6879?
CVE-2023-6879 has been classified as a high-severity vulnerability due to the potential for a heap overflow.
2
How do I fix CVE-2023-6879?
To fix CVE-2023-6879, update the AOMedia software to version 3.7.1 or later, or ensure you are using a patched version on Fedora systems.
3
What software is affected by CVE-2023-6879?
CVE-2023-6879 affects AOMedia versions below 3.7.1 and Fedora versions 38 and 39.
4
What are the consequences of exploiting CVE-2023-6879?
Exploitation of CVE-2023-6879 can lead to application crashes and potentially allow remote code execution.
5
What components in AOMedia are vulnerable due to CVE-2023-6879?
CVE-2023-6879 specifically impacts the av1_loop_restoration_dealloc() function during multi-threaded video frame encoding.