<?xml version="1.0" encoding="utf-8"?>
  <?xml-stylesheet type="text/xsl" href="sa-render.xsl"?>
  <update from="huaweicloud.com" type="security" status="stable" version="1">
    <id>HCE2-SA-2025-0306</id>
    <title>An update for dav1d is now available for HCE 2.0</title>
    <severity>Important</severity>
    <release>HCE 2.0</release>
    <issued date="2025-12-09 06:53:37"/>
    <updated date="2025-12-09 06:53:37"/>
    <references>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2024-1580" id="CVE-2024-1580" title="CVE-2024-1580 Base Score: 8.8 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" type="cve"/>
    </references>
    <description>Security Fix(es):

An integer overflow in dav1d AV1 decoder that can occur when decoding videos with large frame size. This can lead to memory corruption within the AV1 decoder. We recommend upgrading past version 1.4.0 of dav1d. (CVE-2024-1580)
</description>
    <pkglist>
      <collection short="HCE 2.0" package="dav1d">
        <name>HCE 2.0</name>
        <package arch="x86_64" name="libdav1d" version="0.5.2" release="2.r2.hce2">
          <filename>libdav1d-0.5.2-2.r2.hce2.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="libdav1d-devel" version="0.5.2" release="2.r2.hce2">
          <filename>libdav1d-devel-0.5.2-2.r2.hce2.x86_64.rpm</filename>
        </package>
        <package arch="aarch64" name="libdav1d" version="0.5.2" release="2.r2.hce2">
          <filename>libdav1d-0.5.2-2.r2.hce2.aarch64.rpm</filename>
        </package>
        <package arch="aarch64" name="libdav1d-devel" version="0.5.2" release="2.r2.hce2">
          <filename>libdav1d-devel-0.5.2-2.r2.hce2.aarch64.rpm</filename>
        </package>
      </collection>
    </pkglist>
  </update>
