PT-2026-50982 · Aomedia · Libaom
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
libaom (affected versions not specified)
Description
An arbitrary address write issue exists in the reference AV1 codec implementation. A missing bounds check in the Scalable Video Coding (SVC) layer ID control function allows an attacker to inject an arbitrary pointer into the cyclic refresh map field by using crafted image pixel values. Consequently, the encoder writes approximately 1,200 bytes to an address controlled by the attacker. This process is fully deterministic and does not require a separate information leak. An attacker providing frames to a network-facing encoder with SVC enabled could cause a denial of service or achieve potential code execution.
Recommendations
Apply the aomedia patched build (commit a93ba0ffaa) or a vendor update.
As a temporary mitigation, disable SVC in the libaom encoder.
Fix
DoS
RCE
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Libaom