CVE-2026-56208 Details
Description
A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation. A flaw in the AV1 encoder's Look-Ahead Processing (LAP) mode causes the first-pass stats ring buffer wrap-around guard to be bypassed when g_lag_in_frames is set to 1 or higher. This results in a 232-byte out-of-bounds write on every encoded frame after the second, corrupting adjacent heap objects. An attacker who can influence encoder configuration in a transcoding service or WebRTC session could exploit this to cause a denial of service (process crash) or potentially achieve code execution.
A heap buffer overflow vulnerability has been identified in libaom, the reference AV1 codec implementation. The issue arises in the AV1 encoder's Look-Ahead Processing (LAP) mode, specifically when the 'g_lag_in_frames' parameter is set to 1 or higher. This configuration bypasses the wrap-around guard for the first-pass statistics ring buffer, leading to a 232-byte out-of-bounds write on every encoded frame after the second. The overflow corrupts adjacent heap objects, and an attacker who can influence encoder settings in a transcoding service or WebRTC session could exploit this vulnerability, potentially causing a process crash or arbitrary code execution.
Users can update to libaom version 3.14.0 or later, which includes the patch for this vulnerability. For applications on RHEL-AI 3.4 and Hummingbird 1 that use the standalone libaom package, it is recommended to restrict access to the encoding service to trusted clients only and apply network-level access controls to limit who can submit video for encoding.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 25, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-122 | Heap-based Buffer Overflow | redhat-SADP |
| CWE-122 | Heap-based Buffer Overflow | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
45 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 24, 2026 | CVE Modified | [email protected] |
| Sep 23, 2026 | CVE Modified | [email protected] |
| Sep 22, 2026 | CVE Modified | [email protected] |
| Sep 21, 2026 | CVE Modified | [email protected] |
| Sep 1, 2026 | CVE Modified | redhat-SADP |
| Aug 31, 2026 | CVE Modified | [email protected] |
| Aug 31, 2026 | CVE Modified | [email protected] |
| Aug 28, 2026 | CVE Modified | redhat-SADP |
| Aug 27, 2026 | CVE Modified | redhat-SADP |
| Aug 27, 2026 | CVE Modified | [email protected] |
| Aug 18, 2026 | CVE Modified | redhat-SADP |
| Aug 18, 2026 | CVE Modified | [email protected] |
| Aug 18, 2026 | CVE Modified | [email protected] |
| Aug 13, 2026 | CVE Modified | redhat-SADP |
| Aug 12, 2026 | CVE Modified | [email protected] |
| Aug 12, 2026 | CVE Modified | redhat-SADP |
| Aug 12, 2026 | CVE Modified | [email protected] |
| Aug 12, 2026 | CVE Modified | [email protected] |
| Aug 12, 2026 | CVE Modified | [email protected] |
| Aug 11, 2026 | CVE Modified | [email protected] |
| Aug 7, 2026 | CVE Modified | redhat-SADP |
| Aug 6, 2026 | CVE Modified | [email protected] |
| Aug 3, 2026 | CVE Modified | redhat-SADP |
| Aug 3, 2026 | CVE Modified | [email protected] |
| Jul 29, 2026 | CVE Modified | redhat-SADP |
| Jul 29, 2026 | CVE Modified | [email protected] |
| Jul 28, 2026 | CVE Modified | [email protected] |
| Jul 22, 2026 | CVE Modified | redhat-SADP |
| Jul 22, 2026 | CVE Modified | [email protected] |
| Jul 21, 2026 | CVE Modified | [email protected] |
| Jul 21, 2026 | CVE Modified | [email protected] |
| Jul 15, 2026 | CVE Modified | [email protected] |
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jul 8, 2026 | CVE Modified | [email protected] |
| Jul 7, 2026 | CVE Modified | [email protected] |
| Jul 6, 2026 | CVE Modified | redhat-SADP |
| Jul 3, 2026 | CVE Modified | [email protected] |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 29, 2026 | CVE Modified | [email protected] |
| Jun 25, 2026 | CVE Modified | CISA-ADP |
| Jun 25, 2026 | CVE Modified | CISA-ADP |
| Jun 22, 2026 | CVE Modified | CISA-ADP |
| Jun 22, 2026 | CVE Modified | [email protected] |
| Jun 19, 2026 | CVE Modified | [email protected] |
| Jun 19, 2026 | New CVE Received | [email protected] |