CRITICAL🇵🇱 Wersja polska

CVE-2023-6879

CVSS 9.0v3.1pub. 2023-12-27upd. 2026-06-23

Increasing the resolution of video frames, while performing a multi-threaded encode, can result in a heap overflow in av1_loop_restoration_dealloc().

🤖 AI Analysis
How it works

The bug occurs in the av1_loop_restoration_dealloc() function and is triggered by dynamic resolution change of video frames during an active, multithreaded encoding process. On-the-fly resolution change causes improper heap memory management, leading to heap overflow (CWE-787). An additional risk factor is insufficient input data validation (CWE-20), which enables triggering this code execution path.

Impact

Exploitation of this vulnerability could allow an attacker to execute arbitrary code (RCE) in the context of an application using the AOM library, and in an external exploitation scenario — potentially affecting the confidentiality, integrity, and availability of the system.

Mitigation & patch

Update the AOM library to version v3.7.1 or newer. Users of Fedora distributions should apply patches available through official Fedora update channels in accordance with communications in mailing lists.

Who is affected

AOM library (libaom) before version v3.7.1 and AOM packages in Fedora distributions. Specific Fedora versions are indicated in vendor references.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Aomedia

    APP
    Aomedia
    < 3.7.1
  • Fedora Project Fedora

    OS
    Fedoraproject
    3839
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Memory
CWE
References

Related vulnerabilities

CVE-2024-4577CRITICAL9.8⚠ KEVPL ✓same product

PHP CGI argument injection – RCE na Windows przez mechanizm Best-Fit

CVE-2024-5274CRITICAL9.6⚠ KEVPL ✓same product

Type Confusion w V8 (Google Chrome) — RCE przez spreparowaną stronę HTML

CVE-2024-4947CRITICAL9.6⚠ KEVPL ✓same product

Type Confusion w silniku V8 Chrome — zdalne wykonanie kodu (RCE)

CVE-2024-4671CRITICAL9.6⚠ KEVPL ✓same product

Use-after-free w Google Chrome Visuals umożliwiający ucieczkę z sandbox

CVE-2023-6345CRITICAL9.6⚠ KEVPL ✓same product

Integer overflow w Skia w Google Chrome — sandbox escape