CVE-2026-56208
EUVD-2026-3804519.06.2026, 17:16
A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation. A flaw in the AV1 encoder's Look-Ahead Processing (LAP) mode causes the first-pass stats ring buffer wrap-around guard to be bypassed when g_lag_in_frames is set to 1 or higher. This results in a 232-byte out-of-bounds write on every encoded frame after the second, corrupting adjacent heap objects. An attacker who can influence encoder configuration in a transcoding service or WebRTC session could exploit this to cause a denial of service (process crash) or potentially achieve code execution.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 8 | 0:140.13.0-1.el8_10 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux AI 3.5 for RHEL 9 | 0:3.14.0-1.el9ai ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Hardened Images | 3.14.0-0.1.hum1 ≤ 𝑥 < * | ADP |
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| aom-tools |
| ||||||||||||||||
| libSvtAv1Enc1 |
| ||||||||||||||||
| libaom-devel |
| ||||||||||||||||
| libaom-devel-doc |
| ||||||||||||||||
| libaom3 |
| ||||||||||||||||
| libaom3-32bit |
| ||||||||||||||||
| libyuv-devel-20230517+a377993 |
| ||||||||||||||||
| libyuv-tools-20230517+a377993 |
| ||||||||||||||||
| libyuv0-20230517+a377993 |
| ||||||||||||||||
| libyuv0-32bit-20230517+a377993 |
|
Amazon Linux Releases
References