{"id":"CVE-2023-6879","title":"Increasing the resolution of video frames, while performing a multi-threaded encode, can result in a heap overflow in av1_loop_restoration_dealloc().","summary":"Increasing the resolution of video frames, while performing a multi-threaded encode, can result in a heap overflow in av1_loop_restoration_dealloc().","severity":"critical","cvss":9,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H","cwe":["CWE-20","CWE-787"],"vendor":"aomedia","product":"aomedia","affected":["aomedia < 3.7.1","fedora = 38","fedora = 39"],"patched":["aomedia 3.7.1"],"published":"2023-12-27","updated":"2026-06-23","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2023-6879","references":[{"url":"https://aomedia.googlesource.com/aom/+/refs/tags/v3.7.1","label":"cve-coordination@google.com"},{"url":"https://crbug.com/aomedia/3491","label":"cve-coordination@google.com"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AYONA2XSNFMXLAW4IHLFI5UVV3QRNG5K/","label":"cve-coordination@google.com"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/D6C2HN4T2S6GYNTAUXLH45LQZHK7QPHP/","label":"cve-coordination@google.com"},{"url":"https://aomedia.googlesource.com/aom/+/refs/tags/v3.7.1","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://crbug.com/aomedia/3491","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AYONA2XSNFMXLAW4IHLFI5UVV3QRNG5K/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/D6C2HN4T2S6GYNTAUXLH45LQZHK7QPHP/","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.01175,"epssPercentile":0.65718,"ingestedAt":"2026-06-29T13:24:33.952Z","slug":"CVE-2023-6879","body":"## Overview\n\nIncreasing the resolution of video frames, while performing a multi-threaded encode, can result in a heap overflow in av1_loop_restoration_dealloc().\n\n## Affected\n\n- `aomedia < 3.7.1`\n- `fedora = 38`\n- `fedora = 39`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `aomedia 3.7.1`","depth":"midnight","depthScore":50,"depthScoreParts":{"impact":49.5,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}