A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation. A flaw in the AV1 encoders Look-Ahead Processing (LAP) mode causes the first-pass stats ring buffer wrap-around guard to be bypassed when g_lag_in_frames is set to 1 or higher. This results in a 232-byte out-of-bounds write on every encoded frame after the second, corrupting adjacent heap objects. An attacker who can influence encoder configuration in a transcoding service or WebRTC session could exploit this to cause a denial of service (process crash) or potentially achieve code execution.
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Red Hat Enterprise Linux 10.0 Extended Update Support | RedHat | firefox-0:140.13.0-1.el10_0 | * |
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | RedHat | firefox-0:140.13.0-1.el7_9 | * |
| Red Hat Enterprise Linux 8 | RedHat | firefox-0:140.13.0-1.el8_10 | * |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | RedHat | firefox-0:140.13.0-1.el8_4 | * |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | RedHat | firefox-0:140.13.0-1.el8_4 | * |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | RedHat | firefox-0:140.13.0-1.el8_6 | * |
| Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On | RedHat | firefox-0:140.13.0-1.el8_6 | * |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | RedHat | firefox-0:140.13.0-1.el8_8 | * |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | RedHat | firefox-0:140.13.0-1.el8_8 | * |
| Red Hat Enterprise Linux 9 | RedHat | firefox-0:140.13.0-1.el9_8 | * |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | RedHat | firefox-0:140.13.0-1.el9_2 | * |
| Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions | RedHat | firefox-0:140.13.0-1.el9_4 | * |
| Red Hat Enterprise Linux 9.6 Extended Update Support | RedHat | firefox-0:140.13.0-1.el9_6 | * |
| Red Hat Enterprise Linux AI 3.3 for RHEL 9 | RedHat | aom-0:3.14.0-1.el9ai | * |
| Red Hat Enterprise Linux AI 3.4 for RHEL 9 | RedHat | aom-0:3.14.0-1.el9ai | * |
| Red Hat Enterprise Linux AI 3.5 for RHEL 9 | RedHat | aom-0:3.14.0-1.el9ai | * |
| Red Hat Hardened Images | RedHat | aom-main-3.14.0-0.1.hum1 | * |
| Aom | Ubuntu | questing | * |