{"schema_version":"1.9.0","id":"CVE-2024-5197","published":"2024-06-03T13:30:26.925Z","modified":"2026-08-12T03:51:44.560904517Z","related":["ALSA-2024:5941","ALSA-2024:9827","SUSE-SU-2024:2408-1","SUSE-SU-2024:2409-1","openSUSE-SU-2024:14100-1"],"summary":"Integer overflow in libvpx","details":"There exists interger overflows in libvpx in versions prior to 1.14.1. Calling vpx_img_alloc() with a large value of the d_w, d_h, or align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned vpx_image_t struct may be invalid. Calling vpx_img_wrap() with a large value of the d_w, d_h, or stride_align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned vpx_image_t struct may be invalid. We recommend upgrading to version 1.14.1 or beyond","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/webmproject/libvpx","events":[{"introduced":"0"},{"fixed":"12f3a2ac603e8f10742105519e0cd03c3b8f71dd"}],"database_specific":{"cpe":"cpe:2.3:a:webmproject:libvpx:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"1.14.1"}],"source":"CPE_RANGE"}}],"versions":["v1.14.1-rc1","v1.14.0","v1.14.0-rc1","v1.10.0-rc1","v1.2.0","v1.0.0","v0.9.7-p1","v0.9.7","v0.9.6","v0.9.1","v0.9.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-5197.json"}}],"references":[{"type":"WEB","url":"https://chromium.googlesource.com"},{"type":"WEB","url":"https://chromium.googlesource.com/webm/"},{"type":"WEB","url":"https://g-issues.chromium.org/issues/332382766"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2024/06/msg00005.html"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/5xxx/CVE-2024-5197.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-5197"}],"database_specific":{"cna_assigner":"Google","cwe_ids":["CWE-190"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/5xxx/CVE-2024-5197.json","unresolved_ranges":[{"extracted_events":[{"fixed":"1.14.1"}],"source":"AFFECTED_FIELD"}]},"severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:P/VC:L/VI:H/VA:N/SC:L/SI:L/SA:N"}]}