A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows setting a spatial_layer_id exceeding the configured number of layers. This causes an out-of-bounds heap read of approximately 40,728 bytes when computing a layer context array index. An attacker who can influence SVC encoder parameters in a network-facing service could exploit this for information disclosure (heap content leak) or denial of service (segmentation fault from hitting unmapped memory).
Advisories
Source ID Title
Debian DLA Debian DLA DLA-4774-1 aom security update
Debian DSA Debian DSA DSA-6411-1 aom security update
Ubuntu USN Ubuntu USN USN-8772-1 AOM vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

There is no complete mitigation for this vulnerability. The following measures can reduce risk: 1. If using libaom as a standalone encoder library with SVC enabled, validate that spatial_layer_id does not exceed the number of configured spatial layers before calling aom_codec_control with AV1E_SET_SVC_LAYER_ID. 2. Restrict access to encoding services to trusted clients only. 3. For Firefox and Thunderbird, ensure browsers are updated to versions that include the patched libaom (v3.14.0 or later). 4. Monitor encoding service processes for unexpected crashes (segfaults) that may indicate exploitation attempts.

References
Link Providers
https://access.redhat.com/errata/RHSA-2026:30814 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:42875 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:51100 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:51146 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:60520 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:61627 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:61628 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:61629 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:68634 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:68637 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:68638 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:68639 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:68640 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:68696 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:68697 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:68698 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:68699 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:68708 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:68709 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:68710 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:69927 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:69929 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:69930 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:69931 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:69932 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:69933 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:69934 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:69935 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:71392 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:71393 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:71394 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:71395 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:71396 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:71397 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:71398 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:71399 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:71401 cve-icon cve-icon
https://access.redhat.com/security/cve/CVE-2026-56210 cve-icon cve-icon
https://aomedia.googlesource.com/aom/+/a93ba0ffaa cve-icon cve-icon cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=2490801 cve-icon cve-icon
https://issues.chromium.org/issues/503975732 cve-icon cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2026-56210 cve-icon
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-56210.json cve-icon
https://www.cve.org/CVERecord?id=CVE-2026-56210 cve-icon
History

Thu, 24 Sep 2026 08:30:00 +0000


Tue, 22 Sep 2026 12:30:00 +0000


Mon, 21 Sep 2026 10:45:00 +0000


Mon, 31 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
References

Mon, 31 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:ai_inference_server:3.2::el9
References

Thu, 27 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:openshift_ai:3.4::el9
References

Thu, 06 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:enterprise_linux_ai:3.3::el9
cpe:/a:redhat:enterprise_linux_ai:3.4::el9
References

Tue, 21 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:enterprise_linux_ai:3 cpe:/a:redhat:enterprise_linux_ai:3.5::el9
References

Fri, 03 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat ai Inference Server
Redhat openshift Ai
CPEs cpe:/a:redhat:ai_inference_server:3
cpe:/a:redhat:openshift_ai
Vendors & Products Redhat ai Inference Server
Redhat openshift Ai

Mon, 29 Jun 2026 00:30:00 +0000

Type Values Removed Values Added
References

Wed, 24 Jun 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Aomedia
Aomedia libaom
Redhat hardened Images
Vendors & Products Aomedia
Aomedia libaom
Redhat hardened Images

Mon, 22 Jun 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 20 Jun 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Fri, 19 Jun 2026 18:15:00 +0000

Type Values Removed Values Added
Description A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows setting a spatial_layer_id exceeding the configured number of layers. This causes an out-of-bounds heap read of approximately 40,728 bytes when computing a layer context array index. An attacker who can influence SVC encoder parameters in a network-facing service could exploit this for information disclosure (heap content leak) or denial of service (segmentation fault from hitting unmapped memory).
Title Libaom: libaom: heap-buffer-overflow read via missing bounds check in ctrl_set_layer_id
First Time appeared Redhat
Redhat enterprise Linux
Redhat enterprise Linux Ai
Redhat hummingbird
Weaknesses CWE-125
CPEs cpe:/a:redhat:enterprise_linux_ai:3
cpe:/a:redhat:hummingbird:1
cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
Redhat enterprise Linux Ai
Redhat hummingbird
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-24T08:03:12.532Z

Reserved: 2026-06-19T15:50:16.801Z

Link: CVE-2026-56210

cve-icon Vulnrichment

Updated: 2026-09-01T12:04:46.366Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-06-19T17:16:30.557

Modified: 2026-09-24T09:17:06.640

Link: CVE-2026-56210

cve-icon Redhat

Severity : Important

Publid Date: 2026-06-19T00:00:00Z

Links: CVE-2026-56210 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-06-24T20:41:42Z

Weaknesses