Remote Code Execution Vulnerability in libaom AV1 Codec by AOMedia
CVE-2026-56211
Key Information:
- Vendor
Red Hat
- Status
- Vendor
- CVE Published:
- 19 June 2026
What is CVE-2026-56211?
A vulnerability in the libaom AV1 codec, specifically related to insufficient bounds validation within the SVC layer ID control, can be exploited for remote code execution. Attackers may provide specially crafted video frame pixels, leading to memory overlaps with internal structures of the encoder. This flaw enables adversaries to hijack the cyclic refresh map pointer and manipulate the process during video encoding, potentially allowing arbitrary command execution through targeted attacks on services utilizing libaom with SVC encoding enabled.
Affected Version(s)
Red Hat Enterprise Linux AI 3.3 for RHEL 9 0:3.14.0-1.el9ai
Red Hat Enterprise Linux AI 3.4 for RHEL 9 0:3.14.0-1.el9ai
Red Hat Enterprise Linux AI 3.5 for RHEL 9 0:3.14.0-1.el9ai
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved