Security Advisory

CVE-2026-56210

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-06-19 16:28:33
Last updated 2026-07-22 12:08:40
Assigner redhat
CVSS score not scored
State PUBLISHED

Description

A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows setting a spatial_layer_id exceeding the configured number of layers. This causes an out-of-bounds heap read of approximately 40,728 bytes when computing a layer context array index. An attacker who can influence SVC encoder parameters in a network-facing service could exploit this for information disclosure (heap content leak) or denial of service (segmentation fault from hitting unmapped memory).