View at Official debian advisory, NVD, CVE.org · CVE detail
Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.
CVE-2024-1580 not yet assigned priority: Debian including 1 source packages (dav1d), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5.
An integer overflow in dav1d AV1 decoder that can occur when decoding videos with large frame size. This can lead to memory corruption within the AV1 decoder. We recommend upgrading past version 1.4.0 of dav1d.