Back

MEDIUM

opencv: out-of-bounds read in DIS optflow algorithm when dealing with small images

Published Dec 6, 2019

Description

An out-of-bounds read was discovered in OpenCV before 4.1.1. Specifically, variable coarsest_scale is assumed to be greater than or equal to finest_scale within the calc()/ocl_calc() functions in dis_flow.cpp. However, this is not true when dealing with small images, leading to an out-of-bounds read of the heap-allocated arrays Ux and Uy.

Affected products

Remediation

Red Hat statement

This issue did not affect the versions of OpenCV as shipped with Red Hat Enterprise Linux 6, and 7 as they did not include support for DIS optflow algorithm. This issue affects OpenCV as shipped with Red Hat Enterprise Linux 8. However, the package has been built with C++ standard library hardening (_GLIBCXX_ASSERTIONS) that enables range checks for C++ arrays, vectors, and strings. This leads to an application exit due to an assertion statement and prevents the out-of-bounds read to be exploitable.

Metrics

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 6, 2019
Updated Aug 5, 2024
Reserved Dec 6, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date May 14, 2019
GHSA-JGGW-2Q6G-C3M6