PT-2023-23880 · Videolan+3 · Dav1D+3
Victorien Le Couviour--Tuffet
·
Published
2023-05-09
·
Updated
2025-08-12
·
CVE-2023-32570
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
VideoLAN dav1d versions prior to 1.2.0
Description
The issue is related to a thread task.c race condition that can lead to an application crash. This condition is associated with the dav1d decode frame exit function.
Recommendations
For versions prior to 1.2.0, update to version 1.2.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the dav1d decode frame exit function until a patch is available.
Fix
Race Condition
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Debian
Suse
Dav1D