PT-2026-35334 · Julia · Libaom Jll

Publicado

2026-04-16

·

Atualizado

2026-04-16

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Integer overflow in libaom internal function img alloc helper can lead to heap buffer overflow. This function can be reached via 3 callers:
  • Calling aom img alloc() with a large value of the d w, d h, or align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned aom image t struct may be invalid.
  • Calling aom img wrap() with a large value of the d w, d h, or align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned aom image t struct may be invalid.
  • Calling aom img alloc with border() with a large value of the d w, d h, align, size align, or border parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned aom image t struct may be invalid.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

JLSEC-2026-122

Produtos afetados

Libaom Jll