OSV-2026-55

See a problem?
Import Source
https://github.com/google/oss-fuzz-vulns/blob/main/vulns/libvpx/OSV-2026-55.yaml
JSON Data
https://api.osv.dev/v1/vulns/OSV-2026-55
Published
2026-01-15T00:19:29.465463Z
Modified
2026-01-15T00:19:29.465794Z
Summary
Use-of-uninitialized-value in vp9_quantize_fp_avx2
Details

OSS-Fuzz report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=475583924

Crash type: Use-of-uninitialized-value
Crash state:
vp9_quantize_fp_avx2
block_yrd
vp9_pick_inter_mode
References

Affected packages

OSS-Fuzz / libvpx

Package

Name
libvpx
Purl
pkg:generic/libvpx

Affected ranges

Type
GIT
Repo
https://chromium.googlesource.com/webm/libvpx
Events

Affected versions

v1.*
v1.16.0
v1.16.0-rc1

Ecosystem specific

{
    "severity": "MEDIUM"
}

Database specific

source
"https://github.com/google/oss-fuzz-vulns/blob/main/vulns/libvpx/OSV-2026-55.yaml"
fixed_range
"e83e25f791932202256479052f18bdd03a091147:75d62e849507e78e254d0c2ba47f50174c18d293"