JLSEC-2026-377

Source
https://github.com/JuliaLang/SecurityAdvisories.jl/blob/main/advisories/published/2026/JLSEC-2026-377.md
Import Source
https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-377.json
JSON Data
https://api.osv.dev/v1/vulns/JLSEC-2026-377
Upstream
Published
2026-05-01T13:54:10.329Z
Modified
2026-05-01T14:00:05.888702Z
Summary
[none]
Details

There exists interger overflows in libvpx in versions prior to 1.14.1. Calling vpximgalloc() with a large value of the dw, dh, or align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned vpximaget struct may be invalid. Calling vpximgwrap() with a large value of the dw, dh, or stridealign parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned vpximage_t struct may be invalid. We recommend upgrading to version 1.14.1 or beyond

Database specific
{
    "license": "CC-BY-4.0",
    "sources": [
        {
            "database_specific": {
                "status": "Analyzed"
            },
            "modified": "2025-07-22T18:17:56.937Z",
            "id": "CVE-2024-5197",
            "published": "2024-06-03T14:15:09.520Z",
            "imported": "2026-05-01T13:33:19.993Z",
            "html_url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5197",
            "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2024-5197"
        }
    ]
}
References

Affected packages

Julia / LibVPX_jll

Package

Name
LibVPX_jll
Purl
pkg:julia/LibVPX_jll?uuid=dd192d2f-8180-539f-9fb4-cc70b1dcf69a

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.15.2+0

Database specific

source
"https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-377.json"