Effective Fuzzing: A Dav1d Case Study
ID: ac008e7c-dc0d-5b02-9929-75a3b3f942f7
STIX ID: report--ac008e7c-dc0d-5b02-9929-75a3b3f942f7
Feed Name: Google Project Zero
Threat Score
Nick Galloway (Project Zero) discovered an integer overflow in the dav1d AV1 video decoder that can produce out-of-bounds writes (CVE-2024-1580). The bug was exposed by modifying the existing oss-fuzz target to remove artificial frame-size limits and to fuzz configuration settings (including multithreading), producing proof-of-concept test cases; dav1d 1.4.0 was patched and the report recommends broader fuzzing coverage and consideration of memory-safe parsers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
