CVE-2019-19624: Opencv

Medium severity, CVSS 6.5. EPSS: 1.8% chance of exploitation in the next 30 days.

An out-of-bounds read was discovered in OpenCV before 4.1.1. Specifically, variable coarsest_scale is assumed to be greater than or equal to finest_scale within the calc()/ocl_calc() functions in dis_flow.cpp. However, this is not true when dealing with small images, leading to an out-of-bounds read of the heap-allocated arrays Ux and Uy.

Affected products

  • Opencv Opencv: before 4.1.1 (fixed in 4.1.1)
  • Red Hat Enterprise Linux: version 8.0 only

Published 2019-12-06. Last modified 2026-06-17.