[ GLSA 202310-05 ] dav1d: Denial of Service

[email protected] Sun, 08 Oct 2023 05:42:32 -0000
Newsgroups gmane.linux.gentoo.announce
Message-ID <169674375243.7.12009130815046042486@eaa400207d9c>
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 202310-05
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                           https://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

 Severity: Low
    Title: dav1d: Denial of Service
     Date: October 08, 2023
     Bugs: #906107
       ID: 202310-05

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

A vulnerability has been found in dav1d which could result in denial of
service.

Background
==========

dav1d is an AV1 decoder.

Affected packages
=================

Package           Vulnerable    Unaffected
----------------  ------------  ------------
media-libs/dav1d  < 1.2.0       >= 1.2.0

Description
===========

In some circumstances, dav1d might treat an invalid frame as valid,
resulting in a crash.

Impact
======

Malformed frame data can result in a denial of service.

Workaround
==========

Users should avoid parsing untrusted video with dav1d.

Resolution
==========

All dav1d users should upgrade to the latest version:

  # emerge --sync
  # emerge --ask --oneshot --verbose ">=media-libs/dav1d-1.2.0"

References
==========

[ 1 ] CVE-2023-32570
      https://nvd.nist.gov/vuln/detail/CVE-2023-32570

Availability
============

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

 https://security.gentoo.org/glsa/202310-05

Concerns?
=========

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
[email protected] or alternatively, you may file a bug at
https://bugs.gentoo.org.

License
=======

Copyright 2023 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.

https://creativecommons.org/licenses/by-sa/2.5
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEpqTA6ABLMxh/aChGFMQkOaVy+9kFAmUiQUgACgkQFMQkOaVy
+9nfrg//bYtdIR3KsmLpxZHskQZv0mzYjf05RQbJvqJ31VSqp1bZGRFoz2DZvXfk
I9jBSGlhuPViDjJjILF4ByK3VJgFQCOXwK9ZWe/FtcOOINbwSyE/0tXTywsNrQbb
L7Qvy08fh5YKEaXIM6LG3zqXDaajlNBK5hz/VBbLjz48YS9DmmkijDm772yt7xu2
FWLxXAdHzANHiiT0SbbpvHivX8Y8+rTfccGsvumpGNMxm+fng/tD4srpl6Zs1YX7
PUq1clCz/QxWrAlpv4sz6CIGhx8wbYW7ag9icxba76rN62asrWdT7rRtXrOpIXRf
4jxdrZ0WUfblUvTpGRiytmpWOOTQIgUbPRjWLPRVkR/ZRYQGoIuDXwn8YsZlBIMJ
x9arzQEDxZHOIYNL+P5aCfQEurt/HJBa5MXjLscj/nj827u3zfLU1c54NVty6AXd
u8M3LlnKe5zyzZlCNc5MrXU2uzh4qBq4PWTuzAXVABni8dP1Ika6VF8QvSeazzrM
DwMDRDcaebnF3BGOSrBldmr6+BMbAPbBbyOniwMk7nZ9VP5pEZStGLkjM3sNtwbu
6wLE3hcL9ZnTqcwF9fTkDSoFCZ8C5sEpnQCSP3Awn89t2asAbOw+vI+9DePUQCGh
cKFQEiMoxI3HdiEXENRGGufN/07Waf8NaOUyU5bu2o5gWJPRDHY=
=SXl3
-----END PGP SIGNATURE-----