7.1 HIGH
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): None (N)
- User Interaction (UI): Required (R)
- Scope (S): Unchanged (U)
- Confidentiality (C): Low (L)
- Integrity (I): None (N)
- Availability (A): High (H)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): Required (R)
- Modified Confidentiality (MC): Low (L)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): None (N)
- Modified Availability (MA): High (H)
Activity log
- Created suggestion
Libaom: libaom: heap-buffer-overflow read via missing bounds check in ctrl_set_layer_id
A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows setting a spatial_layer_id exceeding the configured number of layers. This causes an out-of-bounds heap read of approximately 40,728 bytes when computing a layer context array index. An attacker who can influence SVC encoder parameters in a network-facing service could exploit this for information disclosure (heap content leak) or denial of service (segmentation fault from hitting unmapped memory).
References
Affected products
Matching in nixpkgs
pkgs.libaom
Alliance for Open Media AV1 codec library
pkgs.mfaomp
Multiple Files At Once Media Player
pkgs.faust2firefox
The faust2firefox script, part of faust functional programming language for realtime audio signal processing
pkgs.firefox_decrypt
Tool to extract passwords from profiles of Mozilla Firefox and derivates
pkgs.thunderbird-cli
Low-level CLI to manage Mozilla Thunderbird email from the shell
pkgs.thunderbird-mcp
MCP server for Thunderbird - enables AI assistants to access email, contacts, and calendars
pkgs.pkgsRocm.firefox
Web browser built from Firefox source tree
pkgs.firefox-unwrapped
Web browser built from Firefox source tree
pkgs.firefox-gnome-theme
GNOME theme for Firefox
pkgs.firefox-sync-client
Commandline-utility to list/view/edit/delete entries in a firefox-sync account
pkgs.pkgsRocm.firefoxpwa
Tool to install, manage and use Progressive Web Apps (PWAs) in Mozilla Firefox (native component)
pkgs.thunderbird-cli-mcp
MCP server that gives full access to your email through Mozilla Thunderbird
pkgs.firefoxpwa-unwrapped
Tool to install, manage and use Progressive Web Apps (PWAs) in Mozilla Firefox (native component)
pkgs.pkgsRocm.thunderbird
Full-featured e-mail client
pkgs.typstPackages.tiaoma
Barcode and QRCode generator for Typst using Zint
pkgs.firefox-esr-unwrapped
Web browser built from Firefox source tree
-
nixos-unstable 140.11.0esr
- nixpkgs-unstable 140.11.0esr
- nixos-unstable-small 140.11.0esr
-
nixos-26.05 140.11.0esr
- nixos-26.05-small 140.11.0esr
- nixpkgs-26.05-darwin 140.11.0esr
pkgs.pkgsRocm.firefox-beta
Web browser built from Firefox Beta Release source tree
pkgs.thunderbird-unwrapped
Full-featured e-mail client
pkgs.firefox-beta-unwrapped
Web browser built from Firefox Beta Release source tree
pkgs.thunderbird-cli-bridge
HTTP/WebSocket bridge daemon between thunderbird-cli (or any HTTP client) and the Thunderbird-cli WebExtension. Stateless proxy, localhost-only.
pkgs.pkgsRocm.firefox-mobile
Web browser built from Firefox source tree
pkgs.firefox-esr-140-unwrapped
Web browser built from Firefox source tree
-
nixos-unstable 140.11.0esr
- nixpkgs-unstable 140.11.0esr
- nixos-unstable-small 140.11.0esr
-
nixos-26.05 140.11.0esr
- nixos-26.05-small 140.11.0esr
- nixpkgs-26.05-darwin 140.11.0esr
pkgs.thunderbird-140-unwrapped
Full-featured e-mail client
-
nixos-unstable 140.7.2esr
- nixpkgs-unstable 140.11.1esr
- nixos-unstable-small 140.11.1esr
-
nixos-26.05 140.11.1esr
- nixos-26.05-small 140.11.1esr
- nixpkgs-26.05-darwin 140.11.1esr
pkgs.thunderbird-esr-unwrapped
Full-featured e-mail client
-
nixos-unstable 140.7.2esr
- nixpkgs-unstable 140.11.1esr
- nixos-unstable-small 140.11.1esr
-
nixos-26.05 140.11.1esr
- nixos-26.05-small 140.11.1esr
- nixpkgs-26.05-darwin 140.11.1esr
pkgs.pkgsRocm.firefox-unwrapped
Web browser built from Firefox source tree
pkgs.typstPackages.tiaoma_0_1_0
Barcode and QRCode generator for Typst using Zint
pkgs.typstPackages.tiaoma_0_2_0
Barcode and QRCode generator for Typst using Zint
pkgs.typstPackages.tiaoma_0_2_1
Barcode and QRCode generator for Typst using Zint
pkgs.typstPackages.tiaoma_0_3_0
Barcode and QRCode generator for Typst using Zint
pkgs.pkgsRocm.firefox-devedition
Web browser built from Firefox Developer Edition source tree
pkgs.pkgsRocm.thunderbird-latest
Full-featured e-mail client
pkgs.firefox-devedition-unwrapped
Web browser built from Firefox Developer Edition source tree
pkgs.python313Packages.xiaomi-ble
Library for Xiaomi BLE devices
pkgs.python314Packages.xiaomi-ble
Library for Xiaomi BLE devices
pkgs.thunderbird-latest-unwrapped
Full-featured e-mail client
pkgs.pkgsRocm.thunderbird-unwrapped
Full-featured e-mail client
pkgs.pkgsRocm.firefox-beta-unwrapped
Web browser built from Firefox Beta Release source tree
pkgs.thunderbirdPackages.thunderbird
Full-featured e-mail client
pkgs.gnomeExtensions.firefox-profiles
Easily launch Firefox with your favorite profile right from the indicator menu!
pkgs.python313Packages.pyxiaomigateway
Python library to communicate with the Xiaomi Gateway
pkgs.python314Packages.pyxiaomigateway
Python library to communicate with the Xiaomi Gateway
pkgs.roundcubePlugins.thunderbird_labels
None
pkgs.thunderbirdPackages.thunderbird-140
Full-featured e-mail client
-
nixos-unstable 140.7.2esr
- nixpkgs-unstable 140.11.1esr
- nixos-unstable-small 140.11.1esr
-
nixos-26.05 140.11.1esr
- nixos-26.05-small 140.11.1esr
- nixpkgs-26.05-darwin 140.11.1esr
pkgs.thunderbirdPackages.thunderbird-esr
Full-featured e-mail client
-
nixos-unstable 140.7.2esr
- nixpkgs-unstable 140.11.1esr
- nixos-unstable-small 140.11.1esr
-
nixos-26.05 140.11.1esr
- nixos-26.05-small 140.11.1esr
- nixpkgs-26.05-darwin 140.11.1esr
pkgs.pkgsRocm.firefox-devedition-unwrapped
Web browser built from Firefox Developer Edition source tree
pkgs.pkgsRocm.thunderbird-latest-unwrapped
Full-featured e-mail client
pkgs.thunderbirdPackages.thunderbird-latest
Full-featured e-mail client
pkgs.pkgsRocm.thunderbirdPackages.thunderbird
Full-featured e-mail client
pkgs.gnomeExtensions.firefox-pip-always-on-top
Automatically sets Picture-in-Picture windows to always be on top and visible on all workspaces
pkgs.gnomeExtensions.pip-alwaysontop-for-firefox
Enable Picture-in-Picture(PIP) mode to always be on for Firefox in Gnome.
pkgs.home-assistant-custom-components.xiaomi_home
Xiaomi Home Integration for Home Assistant
pkgs.home-assistant-custom-components.xiaomi_miot
Automatic integrate all Xiaomi devices to HomeAssistant via miot-spec, support Wi-Fi, BLE, ZigBee devices
pkgs.pkgsRocm.thunderbirdPackages.thunderbird-latest
Full-featured e-mail client
pkgs.home-assistant-custom-components.xiaomi_gateway3
Home Assistant custom component for control Xiaomi Multimode Gateway (aka Gateway 3), Xiaomi Multimode Gateway 2, Aqara Hub E1 on default firmwares over LAN
pkgs.vscode-extensions.firefox-devtools.vscode-firefox-debug
Visual Studio Code extension for debugging web applications and browser extensions in Firefox
Package maintainers
-
@pmahoney Patrick Mahoney <pat@polycrystal.org>
-
@magnetophon Bart Brouns <bart@magnetophon.nl>
-
@jopejoe1 jopejoe1 <nixpkgs@missing.ninja>
-
@rhendric Ryan Hendrickson
-
@mweinelt Martin Weinelt <hexa@darmstadt.ccc.de>
-
@nekowinston winston <hey@winston.sh>
-
@ambroisie Bruno BELANYI <bruno.nixpkgs@belanyi.fr>
-
@booxter Ihar Hrachyshka <ihar.hrachyshka@gmail.com>
-
@unode Renato Alves <alves.rjc@gmail.com>
-
@schnusch schnusch
-
@pasqui23 pasqui23 <p3dimaria@hotmail.it>
-
@camillemndn Camille M. <camillemondon@free.fr>
-
@honnip Jung seungwoo <me@honnip.page>
-
@azuwis Zhong Jianxin <azuwis@gmail.com>
-
@MakiseKurisu Makise Kurisu
-
@JamieMagee Jamie Magee <jamie.magee@gmail.com>
-
@D4ndellion Daniel Olsen <daniel@dodsorf.as>
-
@Neurofibromin Neurofibromin
-
@lovesegfault Bernardo Meurer <meurerbernardo@gmail.com>
-
@nbp Nicolas B. Pierron <nixos@nbp.name>
-
@vcunat Vladimír Čunát <v@cunat.cz>
-
@fabaff Fabian Affolter <mail@fabian-affolter.ch>
-
@drupol Pol Dellaiera <pol.dellaiera@protonmail.com>
-
@cherrypiejam Gongqi Huang
-
@RossSmyth Ross Smyth
-
@felschr Felix Schröter <dev@felschr.com>