Increasing the resolution of video frames, while performing a multi-threaded encode, can result in a heap overflow in av1_loop_restoration_dealloc().
The bug occurs in the av1_loop_restoration_dealloc() function and is triggered by dynamic resolution change of video frames during an active, multithreaded encoding process. On-the-fly resolution change causes improper heap memory management, leading to heap overflow (CWE-787). An additional risk factor is insufficient input data validation (CWE-20), which enables triggering this code execution path.
Exploitation of this vulnerability could allow an attacker to execute arbitrary code (RCE) in the context of an application using the AOM library, and in an external exploitation scenario — potentially affecting the confidentiality, integrity, and availability of the system.
Update the AOM library to version v3.7.1 or newer. Users of Fedora distributions should apply patches available through official Fedora update channels in accordance with communications in mailing lists.
AOM library (libaom) before version v3.7.1 and AOM packages in Fedora distributions. Specific Fedora versions are indicated in vendor references.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:HAomedia
APPAomedia< 3.7.1Fedora Project Fedora
OSFedoraproject3839
Related vulnerabilities
PHP CGI argument injection – RCE na Windows przez mechanizm Best-Fit
Type Confusion w V8 (Google Chrome) — RCE przez spreparowaną stronę HTML
Type Confusion w silniku V8 Chrome — zdalne wykonanie kodu (RCE)
Use-after-free w Google Chrome Visuals umożliwiający ucieczkę z sandbox
Integer overflow w Skia w Google Chrome — sandbox escape