logo

Effective Fuzzing: A Dav1d Case Study

ID: ac008e7c-dc0d-5b02-9929-75a3b3f942f7

STIX ID: report--ac008e7c-dc0d-5b02-9929-75a3b3f942f7

Feed Name: Google Project Zero

Threat Score
65/100

Date Published: 2024-10-03

Date Updated: 2026-04-27

Author: Unknown

...
...

Nick Galloway (Project Zero) discovered an integer overflow in the dav1d AV1 video decoder that can produce out-of-bounds writes (CVE-2024-1580). The bug was exposed by modifying the existing oss-fuzz target to remove artificial frame-size limits and to fuzz configuration settings (including multithreading), producing proof-of-concept test cases; dav1d 1.4.0 was patched and the report recommends broader fuzzing coverage and consideration of memory-safe parsers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.