← All Advisories

CVE-2026-56208

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-56208

Key Details

CVECVE-2026-56208
CVSS Score / Version7.6 (High) / CVSS v3.1
Updated2026-10-02
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is required; scope is unchanged; confidentiality impact is low; integrity impact is low; availability impact is high.
Affected productssee table below
Classified asCWE-122 (Heap-based Buffer Overflow)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Red HatRed Hat AI Inference Server 3.3
Red HatRed Hat OpenShift AI 3.3
Red HatRed Hat OpenShift AI 3.4
Red HatRed Hat AI Inference Server
Red HatRed Hat OpenShift AI (RHOAI)
Red HatRed Hat Enterprise Linux 10
Red HatRed Hat Enterprise Linux 10.0 Extended Update Support
Red HatRed Hat Enterprise Linux 8
Red HatRed Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
Red HatRed Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
Red HatRed Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
Red HatRed Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On
Red HatRed Hat Enterprise Linux 8.8 Telecommunications Update Service
Red HatRed Hat Enterprise Linux 8.8 Update Services for SAP Solutions
Red HatRed Hat Enterprise Linux 9
Red HatRed Hat Enterprise Linux 9.2 Update Services for SAP Solutions
Red HatRed Hat Enterprise Linux 9.4 Update Services for SAP Solutions
Red HatRed Hat Enterprise Linux 9.6 Extended Update Support
Red HatRed Hat OpenShift AI 3.5
Red HatRed Hat Hardened Images
Red HatRed Hat Enterprise Linux 7 Extended Lifecycle Support
Red HatRed Hat AI Inference Server 3.2
Red HatRed Hat Enterprise Linux AI 3.3 for RHEL 9
Red HatRed Hat Enterprise Linux AI 3.4 for RHEL 9
Red HatRed Hat Enterprise Linux AI 3.5 for RHEL 9
SubsystemsGeneral OT
SectorsMultiple

What to Know

A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation. A flaw in the AV1 encoder's Look-Ahead Processing (LAP) mode causes the first-pass stats ring buffer wrap-around guard to be bypassed when g_lag_in_frames is set to 1 or higher. This results in a 232-byte out-of-bounds write on every encoded frame after the second, corrupting adjacent heap objects. An attacker who can influence encoder configuration in a transcoding service or WebRTC session could exploit this to cause a denial of service (process crash) or potentially achieve code execution. (NVD)

What to Do

Monitor Red Hat's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-56208
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-56208