Heap Buffer Overflow in libaom AV1 Codec Implementation
CVE-2026-56210
7.1HIGH
Key Information:
- Vendor
Red Hat
- Status
- Vendor
- CVE Published:
- 19 June 2026
What is CVE-2026-56210?
A heap-buffer-overflow read vulnerability exists in libaom, the AV1 codec. The flaw arises due to a missed bounds check in the SVC layer ID control function, permitting an attacker to manipulate the spatial_layer_id and exceed the set layer count. This results in a read of sensitive heap memory, potentially disclosing information or causing service disruption through segmentation faults when accessing unmapped memory regions.
Affected Version(s)
Red Hat Enterprise Linux AI 3.5 for RHEL 9 0:3.14.0-1.el9ai
Red Hat Hardened Images 3.14.0-0.1.hum1
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank The FuzzAnything Team (FuzzAnything) for reporting this issue.