CVE-2024-5197
There exists interger overflows in libvpx in versions prior to 1.14.1. Calling vpx_img_alloc() with a large value of the d_w, d_h, or align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned vpx_image_t struct may be invalid. Calling vpx_img_wrap() with a large value of the d_w, d_h, or stride_align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned vpx_image_t struct may be invalid. We recommend upgrading to version 1.14.1 or beyond
- Affected products
- Alt Linux, Almalinux, Astra Linux, Centos, Linuxmint, Red Hat, Red Os, Rocky Linux
- Webmproject Libvpx
- < 1.14.1
- Fix
- Available
- CVSS 3.1
- 9.1 CRITICAL
- EPSS
- 0.8% (54th percentile)
- Weakness
- CWE-190
- NVD status
- Analyzed
- Published
- 2024-06-03
- Attack patterns
- CAPEC-100
No indexed exploits for CVE-2024-5197 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2024-5197 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.