PT-2026-50981 · Libaom+1 · Libaom+1

·

CVE-2026-56208

·

Published

2026-06-19

·

Updated

2026-07-29

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions libaom (affected versions not specified)
Description A heap buffer overflow occurs in the reference AV1 codec implementation. A flaw in the AV1 encoder's Look-Ahead Processing (LAP) mode allows the first-pass stats ring buffer wrap-around guard to be bypassed when the g lag in frames variable is set to 1 or higher. This leads to a 232-byte out-of-bounds write on every encoded frame after the second, which corrupts adjacent heap objects. An attacker capable of influencing encoder configuration in a WebRTC session or transcoding service could cause a denial of service via a process crash or potentially achieve code execution.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

DoS

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56208
ECHO-C281-5876-5F69
OPENSUSE-SU-2026:21061-1
RHSA-2026:30814
RHSA-2026:42875
SUSE-SU-2026:22369-1
SUSE-SU-2026:2829-1
SUSE-SU-2026:3224-1

Affected Products

Rocky Linux
Libaom