Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2023-6879: AOM encoder may overflow memory on high-resolution multi-threaded video

CVE-2023-6879 · published 2 years ago
Summary

The AOM video encoding library used in Debian and BellSoft packages can run out of memory when it processes very high-resolution video frames using multiple threads. This can cause the program to crash or behave unpredictably. Updating to the latest version of the AOM package or applying the provided patch will prevent the issue.

What to do
  • Update debian rootio-aom to version 1.0.0.errata1-3+deb11u2.root.io.7.
  • Update debian rootio-aom to version 3.6.0-1+deb12u2.root.io.10.
  • Update debian aom to version 1.0.0.errata1-3+deb11u2.root.io.8.
  • Update debian rootio-aom to version 1.0.0.errata1-3+deb11u2.root.io.8.
  • Update bellsoft aom to version 3.7.1-r0.
  • Update aom to version 3.6.0-1+deb12u3.aikido.15.
  • Update rootio-aom to version 3.6.0-1+deb12u3.aikido.15.
  • Update debian aom to version 3.7.1-1.
Affected software
Ecosystem VendorProductAffected versions
Root:Debian:11 debian rootio-aom < 1.0.0.errata1-3+deb11u2.root.io.7
< 1.0.0.errata1-3+deb11u2.root.io.8
Fix: upgrade to 1.0.0.errata1-3+deb11u2.root.io.7
Root:Debian:12 debian rootio-aom < 3.6.0-1+deb12u2.root.io.10
Fix: upgrade to 3.6.0-1+deb12u2.root.io.10
Root:Debian:11 debian aom < 1.0.0.errata1-3+deb11u2.root.io.8
Fix: upgrade to 1.0.0.errata1-3+deb11u2.root.io.8
Alpaquita:23 bellsoft aom >= 3.5.0-r0, < 3.7.1-r0
Fix: upgrade to 3.7.1-r0
BellSoft Hardened Containers:23 bellsoft aom >= 3.5.0-r0, < 3.7.1-r0
Fix: upgrade to 3.7.1-r0
Root:Debian:12 – aom < 3.6.0-1+deb12u3.aikido.15
Fix: upgrade to 3.6.0-1+deb12u3.aikido.15
Root:Debian:12 – rootio-aom < 3.6.0-1+deb12u3.aikido.15
Fix: upgrade to 3.6.0-1+deb12u3.aikido.15
Debian:12 debian aom All versions
Debian:13 debian aom < 3.7.1-1
Fix: upgrade to 3.7.1-1
Ubuntu:20.04:LTS canonical aom All versions
Original advisory text
Increasing the resolution of video frames, while performing a multi-threaded encode, can result in a heap overflow in av1_loop_restoration_dealloc().
Increasing the resolution of video frames, while performing a multi-threaded encode, can result in a heap overflow in av1_loop_restoration_dealloc().
Severity
9.8 Critical
CVSS 3.1: 9.8 (OSV)
Exploitation
EPSS 1%
Timeline
Published27 Dec 2023
Updated22 Sep 2026
First seen23 Jun 2026
Track software like this
Free during beta