First published: Mon Feb 19 2024(Updated: )
An integer overflow in dav1d AV1 decoder that can occur when decoding videos with large frame size. This can lead to memory corruption within the AV1 decoder. We recommend upgrading past version 1.4.0 of dav1d.
Credit: cve-coordination@google.com Nick Galloway Google Project ZeroNick Galloway Google Project ZeroNick Galloway Google Project ZeroNick Galloway Google Project ZeroNick Galloway Google Project Zero
Affected Software | Affected Version | How to fix |
---|---|---|
Apple macOS | <14.4.1 | 14.4.1 |
Apple Mobile Safari | <17.4.1 | 17.4.1 |
Apple iOS, iPadOS, and watchOS | <16.7.7 | 16.7.7 |
Apple iOS, iPadOS, and watchOS | <16.7.7 | 16.7.7 |
Apple iOS, iPadOS, and watchOS | <17.4.1 | 17.4.1 |
Apple iOS, iPadOS, and watchOS | <17.4.1 | 17.4.1 |
visionOS | <1.1.1 | 1.1.1 |
macOS Ventura | <13.6.6 | 13.6.6 |
libdav1d | <1.4.0 | |
Apple Mobile Safari | <17.4.1 | |
Apple iOS, iPadOS, and watchOS | <16.7.7 | |
Apple iOS, iPadOS, and watchOS | >=17.0<17.4.1 | |
iStyle @cosme iPhone OS | <16.7.7 | |
iStyle @cosme iPhone OS | >=17.0<17.4.1 | |
Apple iOS and macOS | >=13.0<13.6.6 | |
Apple iOS and macOS | >=14.0<14.4.1 | |
visionOS | <1.1.1 | |
Fedora | =40 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2024-1580 has been classified as a high-severity vulnerability due to potential memory corruption issues.
To fix CVE-2024-1580, you should upgrade to versions 1.4.0 or later of dav1d and ensure your Apple devices are updated to the recommended versions.
CVE-2024-1580 affects various Apple products including iOS, iPadOS, Safari, and macOS versions prior to the specified remedies.
CVE-2024-1580 is an integer overflow vulnerability in the dav1d AV1 decoder.
If you do not update your software for CVE-2024-1580, you risk memory corruption which could lead to application crashes or data breaches.