PT-2026-39706 · Julia · Libvpx Jll

Publicado

2026-05-01

·

Atualizado

2026-05-01

CVSS v3.1

9.1

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
There exists interger overflows in libvpx in versions prior to 1.14.1. Calling vpx img alloc() with a large value of the d w, d h, or align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned vpx image t struct may be invalid. Calling vpx img wrap() with a large value of the d w, d h, or stride align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned vpx image t struct may be invalid. We recommend upgrading to version 1.14.1 or beyond

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

JLSEC-2026-377

Produtos afetados

Libvpx Jll