OSV-2026-30

See a problem?
Import Source
https://github.com/google/oss-fuzz-vulns/blob/main/vulns/libvpx/OSV-2026-30.yaml
JSON Data
https://api.test.osv.dev/v1/vulns/OSV-2026-30
Published
2026-01-11T00:08:32.391680Z
Modified
2026-01-16T03:37:34.281633Z
Summary
Use-of-uninitialized-value in vp9_quantize_fp_avx2
Details

OSS-Fuzz report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=474614578

Crash type: Use-of-uninitialized-value
Crash state:
vp9_quantize_fp_avx2
block_yrd
vp9_pick_inter_mode
References

Affected packages

OSS-Fuzz / libvpx

Package

Name
libvpx
Purl
pkg:generic/libvpx

Affected ranges

Type
GIT
Repo
https://chromium.googlesource.com/webm/libvpx
Events

Ecosystem specific

{
    "severity": "MEDIUM"
}

Database specific

fixed_range
"3383144ae67b9539279dd72ea236d29270e56da4:1a400b808407a49d6ee626e8e6015c5cd9df6298"
source
"https://github.com/google/oss-fuzz-vulns/blob/main/vulns/libvpx/OSV-2026-30.yaml"