Heap Buffer Overflow Vulnerability in libaom Reference AV1 Codec Implementation
CVE-2026-56208
Key Information:
What is CVE-2026-56208?
A heap buffer overflow vulnerability has been identified in the libaom AV1 codec implementation. This issue arises from a flaw in the Look-Ahead Processing (LAP) mode of the AV1 encoder, where the first-pass statistics ring buffer wrap-around guard is bypassed when g_lag_in_frames is set to 1 or higher. This vulnerability allows for a 232-byte out-of-bounds write for every encoded frame following the second one, which can corrupt adjacent heap objects. Attackers capable of modifying the encoder configuration in a transcoding service or WebRTC session may exploit this flaw, potentially resulting in a process crash or allowing unauthorized code execution.
Affected Version(s)
Red Hat Enterprise Linux 10.0 Extended Update Support 0:140.13.0-1.el10_0
Red Hat Enterprise Linux 7 Extended Lifecycle Support 0:140.13.0-1.el7_9
Red Hat Enterprise Linux 8 0:140.13.0-1.el8_10
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved