CVE-2026-56210 Details
Description
A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows setting a spatial_layer_id exceeding the configured number of layers. This causes an out-of-bounds heap read of approximately 40,728 bytes when computing a layer context array index. An attacker who can influence SVC encoder parameters in a network-facing service could exploit this for information disclosure (heap content leak) or denial of service (segmentation fault from hitting unmapped memory).
A heap-buffer-overflow read vulnerability has been identified in libaom, the reference AV1 codec implementation. This vulnerability arises from a missing bounds check in the Scalable Video Coding (SVC) layer ID control function, which allows the spatial_layer_id to be set beyond the configured limit. As a result, an out-of-bounds heap read of approximately 40,728 bytes occurs when the encoder computes a layer context array index. This vulnerability could be exploited by an attacker who can influence SVC encoder parameters in a network-facing service, leading to information disclosure through a heap content leak or causing a denial-of-service by triggering a segmentation fault from accessing unmapped memory.
Update libaom to version 3.14.0 or later, where this vulnerability has been fixed by adding proper bounds validation to the layer ID control functions. For Red Hat users, ensure that Firefox and Thunderbird are updated to versions that include the patched libaom.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | redhat-SADP |
| CWE-125 | Out-of-bounds Read | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
29 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 24, 2026 | CVE Modified | [email protected] |
| Sep 22, 2026 | CVE Modified | [email protected] |
| Sep 21, 2026 | CVE Modified | [email protected] |
| Sep 1, 2026 | CVE Modified | redhat-SADP |
| Aug 31, 2026 | CVE Modified | [email protected] |
| Aug 31, 2026 | CVE Modified | [email protected] |
| Aug 28, 2026 | CVE Modified | redhat-SADP |
| Aug 27, 2026 | CVE Modified | redhat-SADP |
| Aug 27, 2026 | CVE Modified | [email protected] |
| Aug 18, 2026 | CVE Modified | [email protected] |
| Aug 12, 2026 | CVE Modified | redhat-SADP |
| Aug 11, 2026 | CVE Modified | [email protected] |
| Aug 7, 2026 | CVE Modified | redhat-SADP |
| Aug 6, 2026 | CVE Modified | [email protected] |
| Jul 29, 2026 | CVE Modified | redhat-SADP |
| Jul 29, 2026 | CVE Modified | [email protected] |
| Jul 22, 2026 | CVE Modified | redhat-SADP |
| Jul 21, 2026 | CVE Modified | [email protected] |
| Jul 21, 2026 | CVE Modified | [email protected] |
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jul 8, 2026 | CVE Modified | [email protected] |
| Jul 6, 2026 | CVE Modified | [email protected] |
| Jul 6, 2026 | CVE Modified | redhat-SADP |
| Jul 3, 2026 | CVE Modified | [email protected] |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 29, 2026 | CVE Modified | [email protected] |
| Jun 22, 2026 | CVE Modified | CISA-ADP |
| Jun 19, 2026 | CVE Modified | [email protected] |
| Jun 19, 2026 | New CVE Received | [email protected] |