Arbitrary Address Write Vulnerability in libaom AV1 Codec Implementation
CVE-2026-56209
Key Information:
- Vendor
Red Hat
- Status
- Vendor
- CVE Published:
- 19 June 2026
What is CVE-2026-56209?
A vulnerability in the libaom AV1 codec implementation allows for arbitrary address writes due to a missing bounds check in the SVC (Scalable Video Coding) layer ID control function. Attackers can exploit this flaw by supplying specially crafted image pixel values to the encoder, leading to the injection of an arbitrary pointer. This enables the encoder to write approximately 1,200 bytes to an address controlled by the attacker. Successful exploitation can result in denial of service or the potential for arbitrary code execution, particularly if the libaom encoder is exposed to network requests.
Affected Version(s)
Red Hat Enterprise Linux AI 3.5 for RHEL 9 0:3.14.0-1.el9ai
Red Hat Hardened Images 3.14.0-0.1.hum1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved