Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2023-6879: AOM encoder may overflow memory on high-resolution multi-threaded video
CVE-2023-6879 · published 2 years ago
Summary
The AOM video encoding library used in Debian and BellSoft packages can run out of memory when it processes very high-resolution video frames using multiple threads. This can cause the program to crash or behave unpredictably. Updating to the latest version of the AOM package or applying the provided patch will prevent the issue.
What to do
- Update debian rootio-aom to version 1.0.0.errata1-3+deb11u2.root.io.7.
- Update debian rootio-aom to version 3.6.0-1+deb12u2.root.io.10.
- Update debian aom to version 1.0.0.errata1-3+deb11u2.root.io.8.
- Update debian rootio-aom to version 1.0.0.errata1-3+deb11u2.root.io.8.
- Update bellsoft aom to version 3.7.1-r0.
- Update aom to version 3.6.0-1+deb12u3.aikido.15.
- Update rootio-aom to version 3.6.0-1+deb12u3.aikido.15.
- Update debian aom to version 3.7.1-1.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Root:Debian:11 | debian | rootio-aom |
< 1.0.0.errata1-3+deb11u2.root.io.7 < 1.0.0.errata1-3+deb11u2.root.io.8 Fix: upgrade to 1.0.0.errata1-3+deb11u2.root.io.7
|
| Root:Debian:12 | debian | rootio-aom |
< 3.6.0-1+deb12u2.root.io.10 Fix: upgrade to 3.6.0-1+deb12u2.root.io.10
|
| Root:Debian:11 | debian | aom |
< 1.0.0.errata1-3+deb11u2.root.io.8 Fix: upgrade to 1.0.0.errata1-3+deb11u2.root.io.8
|
| Alpaquita:23 | bellsoft | aom |
>= 3.5.0-r0, < 3.7.1-r0 Fix: upgrade to 3.7.1-r0
|
| BellSoft Hardened Containers:23 | bellsoft | aom |
>= 3.5.0-r0, < 3.7.1-r0 Fix: upgrade to 3.7.1-r0
|
| Root:Debian:12 | – | aom |
< 3.6.0-1+deb12u3.aikido.15 Fix: upgrade to 3.6.0-1+deb12u3.aikido.15
|
| Root:Debian:12 | – | rootio-aom |
< 3.6.0-1+deb12u3.aikido.15 Fix: upgrade to 3.6.0-1+deb12u3.aikido.15
|
| Debian:12 | debian | aom | All versions |
| Debian:13 | debian | aom |
< 3.7.1-1 Fix: upgrade to 3.7.1-1
|
| Ubuntu:20.04:LTS | canonical | aom | All versions |
Original advisory text
Increasing the resolution of video frames, while performing a multi-threaded encode, can result in a heap overflow in av1_loop_restoration_dealloc().
Increasing the resolution of video frames, while performing a multi-threaded encode, can result in a heap overflow in av1_loop_restoration_dealloc().
References
- https://docs.bell-sw.com/security/cves/CVE-2023-6879 Vendor Advisory
- https://ubuntu.com/security/CVE-2023-6879 Third Party Advisory
- https://crbug.com/aomedia/3491 Third Party Advisory
- https://aomedia.googlesource.com/aom/+/refs/tags/v3.7.1 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2023-6879 Third Party Advisory
- https://security-tracker.debian.org/tracker/CVE-2023-6879 Vendor Advisory
Severity
9.8
Critical
CVSS 3.1: 9.8 (OSV)
Exploitation
EPSS 1%
Timeline
Published27 Dec 2023
Updated22 Sep 2026
First seen23 Jun 2026
Sources
CVE-2023-6879 · NVD
BELL-CVE-2023-6879 · OSV
DEBIAN-CVE-2023-6879 · OSV
UBUNTU-CVE-2023-6879 · OSV
Track software like this
Free during beta