CVE Vulnerabilities

CVE-2026-56208

Heap-based Buffer Overflow

Published: Jun 19, 2026 | Modified: Sep 24, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
7.6 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation. A flaw in the AV1 encoders Look-Ahead Processing (LAP) mode causes the first-pass stats ring buffer wrap-around guard to be bypassed when g_lag_in_frames is set to 1 or higher. This results in a 232-byte out-of-bounds write on every encoded frame after the second, corrupting adjacent heap objects. An attacker who can influence encoder configuration in a transcoding service or WebRTC session could exploit this to cause a denial of service (process crash) or potentially achieve code execution.

Weakness

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

Affected Software

NameVendorStart VersionEnd Version
Red Hat Enterprise Linux 10.0 Extended Update SupportRedHatfirefox-0:140.13.0-1.el10_0*
Red Hat Enterprise Linux 7 Extended Lifecycle SupportRedHatfirefox-0:140.13.0-1.el7_9*
Red Hat Enterprise Linux 8RedHatfirefox-0:140.13.0-1.el8_10*
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportRedHatfirefox-0:140.13.0-1.el8_4*
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnRedHatfirefox-0:140.13.0-1.el8_4*
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportRedHatfirefox-0:140.13.0-1.el8_6*
Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-OnRedHatfirefox-0:140.13.0-1.el8_6*
Red Hat Enterprise Linux 8.8 Telecommunications Update ServiceRedHatfirefox-0:140.13.0-1.el8_8*
Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionsRedHatfirefox-0:140.13.0-1.el8_8*
Red Hat Enterprise Linux 9RedHatfirefox-0:140.13.0-1.el9_8*
Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsRedHatfirefox-0:140.13.0-1.el9_2*
Red Hat Enterprise Linux 9.4 Update Services for SAP SolutionsRedHatfirefox-0:140.13.0-1.el9_4*
Red Hat Enterprise Linux 9.6 Extended Update SupportRedHatfirefox-0:140.13.0-1.el9_6*
Red Hat Enterprise Linux AI 3.3 for RHEL 9RedHataom-0:3.14.0-1.el9ai*
Red Hat Enterprise Linux AI 3.4 for RHEL 9RedHataom-0:3.14.0-1.el9ai*
Red Hat Enterprise Linux AI 3.5 for RHEL 9RedHataom-0:3.14.0-1.el9ai*
Red Hat AI Inference Server 3.2RedHatrhaiis/vllm-cuda-rhel9:1787860580*
Red Hat AI Inference Server 3.2RedHatrhaiis/model-opt-cuda-rhel9:1787772157*
Red Hat AI Inference Server 3.2RedHatrhaiis/vllm-rocm-rhel9:1787884873*
Red Hat AI Inference Server 3.3RedHatrhaiis/model-opt-cuda-rhel9:1789508287*
Red Hat AI Inference Server 3.3RedHatrhaiis/vllm-spyre-rhel9:1789502493*
Red Hat AI Inference Server 3.3RedHatrhaiis/vllm-rocm-rhel9:1789504371*
Red Hat AI Inference Server 3.3RedHatrhaiis/vllm-cuda-rhel9:1789582776*
Red Hat Hardened ImagesRedHataom-main-3.14.0-0.1.hum1*
Red Hat OpenShift AI 3.3RedHatrhai/base-image-neuron-rhel9:1789137552*
Red Hat OpenShift AI 3.3RedHatrhai/base-image-rocm-7.0-rhel9:1789137548*
Red Hat OpenShift AI 3.3RedHatrhai/base-image-cuda-13.0-rhel9:1789137636*
Red Hat OpenShift AI 3.3RedHatrhai/base-image-tpu-rhel9:1789137548*
Red Hat OpenShift AI 3.3RedHatrhai/base-image-rocm-6.4-rhel9:1789137548*
Red Hat OpenShift AI 3.3RedHatrhai/base-image-cpu-rhel9:1789137641*
Red Hat OpenShift AI 3.3RedHatrhai/base-image-spyre-rhel9:1789137607*
Red Hat OpenShift AI 3.3RedHatrhai/base-image-cuda-12.9-rhel9:1789137636*
Red Hat OpenShift AI 3.4RedHatrhoai/odh-mlserver-rhel9:1786611800*
Red Hat OpenShift AI 3.4RedHatrhoai/odh-th06-cpu-torch210-py312-rhel9:1787076778*
Red Hat OpenShift AI 3.4RedHatrhoai/odh-th06-cuda130-torch210-py312-rhel9:1787077779*
Red Hat OpenShift AI 3.4RedHatrhoai/odh-th06-rocm64-torch291-py312-rhel9:1787076481*
Red Hat OpenShift AI 3.4RedHatrhai/base-image-tpu-rhel9:1788197680*
Red Hat OpenShift AI 3.4RedHatrhai/base-image-cpu-rhel9:1788197530*
Red Hat OpenShift AI 3.4RedHatrhai/base-image-gaudi-rhel9:1788197632*
Red Hat OpenShift AI 3.4RedHatrhai/base-image-spyre-rhel9:1788197747*
Red Hat OpenShift AI 3.4RedHatrhai/base-image-rocm-7.1-rhel9:1788197549*
Red Hat OpenShift AI 3.4RedHatrhai/base-image-cuda-12.9-rhel9:1788199622*
Red Hat OpenShift AI 3.4RedHatrhai/base-image-cuda-13.0-rhel9:1788197744*
Red Hat OpenShift AI 3.4RedHatrhai/base-image-rocm-6.4-rhel9:1788197677*
Red Hat OpenShift AI 3.5RedHatrhai/base-image-neuron-rhel9:1788198404*
Red Hat OpenShift AI 3.5RedHatrhai/base-image-cpu-rhel9:1788198407*
Red Hat OpenShift AI 3.5RedHatrhai/base-image-tpu-rhel9:1788197492*
Red Hat OpenShift AI 3.5RedHatrhai/base-image-gaudi-rhel9:1788197542*
Red Hat OpenShift AI 3.5RedHatrhai/base-image-cuda-13.0-rhel9:1788197975*
Red Hat OpenShift AI 3.5RedHatrhai/base-image-rubin-rhel9:1788197512*
Red Hat OpenShift AI 3.5RedHatrhai/base-image-spyre-rhel9:1788197688*
Red Hat OpenShift AI 3.5RedHatrhai/base-image-cuda-12.9-rhel9:1788197385*
Red Hat OpenShift AI 3.5RedHatrhai/base-image-rocm-7.14-rhel9:1788198016*
AomUbuntuesm-apps/jammy*
AomUbuntujammy*
AomUbuntunoble*
AomUbuntuquesting*
AomUbunturesolute*
AomUbuntuupstream*

Potential Mitigations

  • Use automatic buffer overflow detection mechanisms that are offered by certain compilers or compiler extensions. Examples include: the Microsoft Visual Studio /GS flag, Fedora/Red Hat FORTIFY_SOURCE GCC flag, StackGuard, and ProPolice, which provide various mechanisms including canary-based detection and range/index checking.
  • D3-SFCV (Stack Frame Canary Validation) from D3FEND [REF-1334] discusses canary-based detection in detail.
  • Run or compile the software using features or extensions that randomly arrange the positions of a program’s executable and libraries in memory. Because this makes the addresses unpredictable, it can prevent an attacker from reliably jumping to exploitable code.
  • Examples include Address Space Layout Randomization (ASLR) [REF-58] [REF-60] and Position-Independent Executables (PIE) [REF-64]. Imported modules may be similarly realigned if their default memory addresses conflict with other modules, in a process known as “rebasing” (for Windows) and “prelinking” (for Linux) [REF-1332] using randomly generated addresses. ASLR for libraries cannot be used in conjunction with prelink since it would require relocating the libraries at run-time, defeating the whole purpose of prelinking.
  • For more information on these techniques see D3-SAOR (Segment Address Offset Randomization) from D3FEND [REF-1335].

References