PT-2019-6432 · Opencv+3 · Opencv-Python+4

·

CVE-2019-19624

·

Published

2019-05-14

·

Updated

2026-07-09

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Name of the Vulnerable Software and Affected Versions OpenCV versions prior to 4.1.1 OpenCV-Python versions prior to 4.1.0.25
Description An out-of-bounds read issue was discovered in the calc() and ocl calc() functions within the dis flow.cpp component of OpenCV. This occurs because the coarsest scale variable is assumed to be greater than or equal to finest scale, which is not true when handling small images. As a result, it leads to an out-of-bounds read of the heap-allocated arrays Ux and Uy. This could potentially allow a remote attacker to access confidential data and cause a denial of service.
Recommendations For OpenCV versions prior to 4.1.1, update to version 4.1.1 or later to resolve the issue. For OpenCV-Python versions prior to 4.1.0.25, update to version 4.1.0.25 or later to resolve the issue. As a temporary workaround, consider restricting the use of the calc() and ocl calc() functions in dis flow.cpp when dealing with small images until a patch is available.

Exploit

Fix

DoS

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-06968
CVE-2019-19624
GHSA-JGGW-2Q6G-C3M6
PYSEC-2026-2800
PYSEC-2026-2824
PYSEC-2026-2839
PYSEC-2026-723
USN-7247-1

Affected Products

Astra Linux
Linuxmint
Opencv
Opencv-Python
Ubuntu