Media decoders have historically been fertile ground for memory safety vulnerabilities. This is because they are complex, heavily used, and commonly processing untrusted data from networks.
AV1 is set to become one of the most important media formats on the Internet. As it becomes more widely used, we want people to have access to a decoder that is as memory safe as reasonably possible while delivering great performance. No such encoder exists today. We are building one.
What We've Done
We've engaged the team at Immunant as well as veteran media codec expert Frank Bossen to work on our decoder, named rav1d. Work started on March 1, 2023.
The team is hard at work!
Milestones 1-4 of our work plan are funded. We're seeking additional funding to complete the remaining milestones.
From our Blog
A Safer High Performance AV1 Decoder
Memory safety for a major source of exploitable vulnerabilities.