CVE-2026-56208
EUVD-2026-3804519.06.2026, 17:16
A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation. A flaw in the AV1 encoder's Look-Ahead Processing (LAP) mode causes the first-pass stats ring buffer wrap-around guard to be bypassed when g_lag_in_frames is set to 1 or higher. This results in a 232-byte out-of-bounds write on every encoded frame after the second, corrupting adjacent heap objects. An attacker who can influence encoder configuration in a transcoding service or WebRTC session could exploit this to cause a denial of service (process crash) or potentially achieve code execution.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10.0 Extended Update Support | 0:140.13.0-1.el10_0 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 7 Extended Lifecycle Support | 0:140.13.0-1.el7_9 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 8 | 0:140.13.0-1.el8_10 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | 0:140.13.0-1.el8_4 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | 0:140.13.0-1.el8_4 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | 0:140.13.0-1.el8_6 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On | 0:140.13.0-1.el8_6 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 8.8 Telecommunications Update Service | 0:140.13.0-1.el8_8 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | 0:140.13.0-1.el8_8 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 9 | 0:140.13.0-1.el9_8 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | 0:140.13.0-1.el9_2 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions | 0:140.13.0-1.el9_4 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 9.6 Extended Update Support | 0:140.13.0-1.el9_6 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux AI 3.3 for RHEL 9 | 0:3.14.0-1.el9ai ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux AI 3.4 for RHEL 9 | 0:3.14.0-1.el9ai ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux AI 3.5 for RHEL 9 | 0:3.14.0-1.el9ai ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Hardened Images | 3.14.0-0.1.hum1 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift AI 3.4 | 1786611800 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift AI 3.4 | 1787076778 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift AI 3.4 | 1787077779 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift AI 3.4 | 1787076481 ≤ 𝑥 < * | ADP |
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| aom-tools |
| ||||||||||||||||||
| libSvtAv1Enc1 |
| ||||||||||||||||||
| libaom-devel |
| ||||||||||||||||||
| libaom-devel-doc |
| ||||||||||||||||||
| libaom3 |
| ||||||||||||||||||
| libaom3-32bit |
| ||||||||||||||||||
| libyuv-devel-20230517+a377993 |
| ||||||||||||||||||
| libyuv-tools-20230517+a377993 |
| ||||||||||||||||||
| libyuv0-20230517+a377993 |
| ||||||||||||||||||
| libyuv0-32bit-20230517+a377993 |
|
Red Hat Enterprise Linux Releases
Amazon Linux Releases
Vulnerability Media Exposure
References