CVE-2026-56210

HIGHCVSS 7.1/10EPSS 0.29%

Last modified

CVE-2026-56210 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows setting a spatial_layer_id exceeding the configured number of layers. EPSS estimates a 0.29% chance of exploitation in the next 30 days.

Description

A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows setting a spatial_layer_id exceeding the configured number of layers. This causes an out-of-bounds heap read of approximately 40,728 bytes when computing a layer context array index. An attacker who can influence SVC encoder parameters in a network-facing service could exploit this for information disclosure (heap content leak) or denial of service (segmentation fault from hitting unmapped memory).

Metrics

CVSS 3.1
7.1/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H

EPSS Probability
0.29%

21.2th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
Red HatRed Hat Enterprise Linux AI 3.3 for RHEL 9All versions
Red HatRed Hat Enterprise Linux AI 3.4 for RHEL 9All versions
Red HatRed Hat Enterprise Linux AI 3.5 for RHEL 9All versions
Red HatRed Hat Hardened ImagesAll versions
Red HatRed Hat AI Inference ServerAll versions
Red HatRed Hat Enterprise Linux 10All versions
Red HatRed Hat Enterprise Linux 9All versions
Red HatRed Hat OpenShift AI (RHOAI)All versions

References

Timeline

Published
Last Modified
Status
Awaiting Analysis

Frequently Asked Questions

What is CVE-2026-56210?
A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows setting a spatial_layer_id exceeding the configured number of layers. This causes an out-of-bounds heap read of approximately 40,728 bytes when computing a layer context array index. An attacker who can influence SVC encoder parameters in a network-facing service could exploit this for information disclosure (heap content leak) or denial of service (segmentation fault from hitting unmapped memory).
How severe is CVE-2026-56210?
CVE-2026-56210 has a CVSS score of 7.1/10 (HIGH severity). The EPSS model estimates a 0.29% probability of exploitation in the next 30 days.
How do I fix CVE-2026-56210?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-56210?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST