An arbitrary address write vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows an attacker to inject an arbitrary pointer into the cyclic refresh map field via crafted image pixel values. The encoder then writes approximately 1,200 bytes at the attacker-controlled address. This is fully deterministic and does not require a separate information leak. An attacker who can supply frames to a network-facing libaom encoder with SVC enabled could exploit this for denial of service or potential code execution.
Advisories
Source ID Title
Debian DLA Debian DLA DLA-4774-1 aom security update
Debian DSA Debian DSA DSA-6411-1 aom security update
Ubuntu USN Ubuntu USN USN-8772-1 AOM vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

There is no complete mitigation for this vulnerability. The following measures can reduce risk: 1. If using libaom as a standalone encoder library with SVC enabled, validate that spatial_layer_id and temporal_layer_id values are within the configured range [0, configured_layers) before calling aom_codec_control with AV1E_SET_SVC_LAYER_ID. 2. Restrict access to encoding services to trusted clients only. Do not expose libaom SVC encoder configuration to untrusted input. 3. For Firefox and Thunderbird, ensure browsers are updated to versions that include the patched libaom (v3.14.0 or later). 4. Deploy encoding services with ASLR, stack canaries, and other exploit mitigation technologies enabled.

References
Link Providers
https://access.redhat.com/errata/RHSA-2026:30814 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:42875 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:51100 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:51146 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:60520 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:61627 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:61628 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:61629 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:68634 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:68637 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:68638 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:68639 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:68640 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:68696 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:68697 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:68698 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:68699 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:68708 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:68709 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:68710 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:69927 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:69929 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:69930 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:69931 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:69932 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:69933 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:69934 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:69935 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:71392 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:71393 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:71394 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:71395 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:71396 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:71397 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:71398 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:71399 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:71401 cve-icon cve-icon
https://access.redhat.com/security/cve/CVE-2026-56209 cve-icon cve-icon
https://aomedia.googlesource.com/aom/+/a93ba0ffaa cve-icon cve-icon cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=2490800 cve-icon cve-icon
https://issues.chromium.org/issues/503993984 cve-icon cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2026-56209 cve-icon
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-56209.json cve-icon
https://www.cve.org/CVERecord?id=CVE-2026-56209 cve-icon
History

Thu, 24 Sep 2026 08:30:00 +0000


Tue, 22 Sep 2026 12:30:00 +0000


Mon, 21 Sep 2026 10:45:00 +0000


Mon, 31 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
References

Mon, 31 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:ai_inference_server:3.2::el9
References

Thu, 27 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:openshift_ai:3.4::el9
References

Thu, 06 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:enterprise_linux_ai:3.3::el9
cpe:/a:redhat:enterprise_linux_ai:3.4::el9
References

Tue, 21 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:enterprise_linux_ai:3 cpe:/a:redhat:enterprise_linux_ai:3.5::el9
References

Fri, 03 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat ai Inference Server
Redhat openshift Ai
CPEs cpe:/a:redhat:ai_inference_server:3
cpe:/a:redhat:openshift_ai
Vendors & Products Redhat ai Inference Server
Redhat openshift Ai

Mon, 29 Jun 2026 01:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 29 Jun 2026 00:30:00 +0000

Type Values Removed Values Added
References

Wed, 24 Jun 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Aomedia
Aomedia libaom
Redhat hardened Images
Vendors & Products Aomedia
Aomedia libaom
Redhat hardened Images

Mon, 22 Jun 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 20 Jun 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Fri, 19 Jun 2026 18:15:00 +0000

Type Values Removed Values Added
Description An arbitrary address write vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows an attacker to inject an arbitrary pointer into the cyclic refresh map field via crafted image pixel values. The encoder then writes approximately 1,200 bytes at the attacker-controlled address. This is fully deterministic and does not require a separate information leak. An attacker who can supply frames to a network-facing libaom encoder with SVC enabled could exploit this for denial of service or potential code execution.
Title Libaom: libaom: arbitrary address write via svc layer context oob and cyclic refresh map pointer hijack
First Time appeared Redhat
Redhat enterprise Linux
Redhat enterprise Linux Ai
Redhat hummingbird
Weaknesses CWE-787
CPEs cpe:/a:redhat:enterprise_linux_ai:3
cpe:/a:redhat:hummingbird:1
cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
Redhat enterprise Linux Ai
Redhat hummingbird
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-24T08:03:06.860Z

Reserved: 2026-06-19T15:50:16.801Z

Link: CVE-2026-56209

cve-icon Vulnrichment

Updated: 2026-09-01T12:04:56.757Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-06-19T17:16:30.427

Modified: 2026-09-24T09:17:06.007

Link: CVE-2026-56209

cve-icon Redhat

Severity : Important

Publid Date: 2026-06-19T00:00:00Z

Links: CVE-2026-56209 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-06-24T20:41:44Z

Weaknesses