There are 2 open security issues in bullseye.
1 important issue:
- CVE-2024-1580:
An integer overflow in dav1d AV1 decoder that can occur when decoding videos with large frame size. This can lead to memory corruption within the AV1 decoder. We recommend upgrading past version 1.4.0 of dav1d.
1 issue left for the package maintainer to handle:
- CVE-2023-32570:
(needs triaging)
VideoLAN dav1d before 1.2.0 has a thread_task.c race condition that can lead to an application crash, related to dav1d_decode_frame_exit.
You can find information about how to handle this issue in the security team's documentation.