A remote code execution vulnerability was found in libaom, the reference AV1 codec implementation. Insufficient bounds validation in the AV1 encoder's SVC (Scalable Video Coding) layer ID control allows an attacker to supply crafted video frame pixels that overlap with internal encoder layer context structures. In fork-based video processing services, an attacker can use this to hijack the cyclic refresh map pointer, brute-force the process base address via a crash oracle, and redirect control flow to achieve arbitrary command execution. Exploitation requires the target service to use libaom with SVC encoding enabled and accept attacker-supplied video frames.
Advisories
Source ID Title
Debian DLA Debian DLA DLA-4774-1 aom security update
Debian DSA Debian DSA DSA-6411-1 aom security update
Ubuntu USN Ubuntu USN USN-8772-1 AOM vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

There is no complete mitigation for this vulnerability. The following measures can reduce risk: 1. If using libaom as a standalone encoder in a fork-based service, validate all SVC layer parameters (spatial_layer_id, temporal_layer_id) against configured bounds before passing them to the encoder API. 2. Avoid fork-based architectures for encoding services that accept untrusted input. Use thread-based or container-isolated workers instead, which prevent crash oracle attacks. 3. Restrict access to encoding services to trusted clients only. Do not expose SVC encoder configuration or frame submission to untrusted network input. 4. For Firefox and Thunderbird, ensure browsers are updated to versions that include the patched libaom (v3.14.0 or later). 5. Enable all available exploit mitigations (ASLR, PIE, stack canaries, CFI) on encoding service binaries.

References
Link Providers
https://access.redhat.com/errata/RHSA-2026:30814 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:42875 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:51100 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:51146 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:60520 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:61627 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:61628 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:61629 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:68634 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:68637 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:68638 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:68639 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:68640 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:68696 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:68697 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:68698 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:68699 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:68708 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:68709 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:68710 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:69927 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:69929 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:69930 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:69931 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:69932 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:69933 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:69934 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:69935 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:71392 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:71393 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:71394 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:71395 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:71396 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:71397 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:71398 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:71399 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:71401 cve-icon cve-icon
https://access.redhat.com/security/cve/CVE-2026-56211 cve-icon cve-icon
https://aomedia.googlesource.com/aom/+/a93ba0ffaa cve-icon cve-icon cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=2490802 cve-icon cve-icon
https://issues.chromium.org/issues/503993985 cve-icon cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2026-56211 cve-icon
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-56211.json cve-icon
https://www.cve.org/CVERecord?id=CVE-2026-56211 cve-icon
History

Thu, 24 Sep 2026 08:30:00 +0000


Tue, 22 Sep 2026 12:30:00 +0000


Mon, 21 Sep 2026 10:45:00 +0000


Mon, 31 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
References

Mon, 31 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:ai_inference_server:3.2::el9
References

Thu, 27 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:openshift_ai:3.4::el9
References

Thu, 06 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:enterprise_linux_ai:3.3::el9
cpe:/a:redhat:enterprise_linux_ai:3.4::el9
References

Tue, 21 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:enterprise_linux_ai:3 cpe:/a:redhat:enterprise_linux_ai:3.5::el9
References

Fri, 03 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat ai Inference Server
Redhat openshift Ai
CPEs cpe:/a:redhat:ai_inference_server:3
cpe:/a:redhat:openshift_ai
Vendors & Products Redhat ai Inference Server
Redhat openshift Ai

Mon, 29 Jun 2026 00:30:00 +0000

Type Values Removed Values Added
References

Thu, 25 Jun 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 24 Jun 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Aomedia
Aomedia libaom
Redhat hardened Images
Vendors & Products Aomedia
Aomedia libaom
Redhat hardened Images

Tue, 23 Jun 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 20 Jun 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Fri, 19 Jun 2026 18:15:00 +0000

Type Values Removed Values Added
Description A remote code execution vulnerability was found in libaom, the reference AV1 codec implementation. Insufficient bounds validation in the AV1 encoder's SVC (Scalable Video Coding) layer ID control allows an attacker to supply crafted video frame pixels that overlap with internal encoder layer context structures. In fork-based video processing services, an attacker can use this to hijack the cyclic refresh map pointer, brute-force the process base address via a crash oracle, and redirect control flow to achieve arbitrary command execution. Exploitation requires the target service to use libaom with SVC encoding enabled and accept attacker-supplied video frames.
Title Libaom: libaom: remote code execution via svc layer context handling with attacker-controlled frames
First Time appeared Redhat
Redhat enterprise Linux
Redhat enterprise Linux Ai
Redhat hummingbird
Weaknesses CWE-787
CPEs cpe:/a:redhat:enterprise_linux_ai:3
cpe:/a:redhat:hummingbird:1
cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
Redhat enterprise Linux Ai
Redhat hummingbird
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-24T08:03:17.514Z

Reserved: 2026-06-19T15:50:16.801Z

Link: CVE-2026-56211

cve-icon Vulnrichment

Updated: 2026-09-01T12:05:00.208Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-06-19T17:16:30.680

Modified: 2026-09-24T09:17:07.250

Link: CVE-2026-56211

cve-icon Redhat

Severity : Important

Publid Date: 2026-06-19T00:00:00Z

Links: CVE-2026-56211 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-06-24T20:41:41Z

Weaknesses