VDB

GCVE-110-MAGEIA-2024-221

GCVE-110-MAGEIA-2024-221
Advisory Published
Vulnetix · Advisory published June 14, 2024
There exists integer overflows in libvpx in versions prior to 1.14.1. Calling vpx_img_alloc() with a large value of the d_w, d_h, or align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned vpx_image_t struct may be invalid. Calling vpx_img_wrap() with a large value of the d_w, d_h, or stride_align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned vpx_image_t struct may be invalid. (CVE-2024-5197)

Affected Products

VendorProductVersionsPlatforms
Mageialibvpx1.12.0-1.3.mga9 (unaffected), 0 (affected), 0 (affected), 1.12.0-1.3.mga9 (unaffected)
Mageialibmateweather0 (affected), 1.26.3-1.mga9 (unaffected)

Browse GCVE Records

73,877 records in the GCVE database · Updated July 20, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›