← All Advisories

CVE-2026-56209

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-56209

Key Details

CVECVE-2026-56209
CVSS Score / Version7.1 (High) / CVSS v3.1
Updated2026-10-02
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is required; scope is unchanged; confidentiality impact is none; integrity impact is low; availability impact is high.
Affected productssee table below
Classified asCWE-787 (Out-of-bounds Write)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Red HatRed Hat AI Inference Server 3.3
Red HatRed Hat OpenShift AI 3.3
Red HatRed Hat OpenShift AI 3.4
Red HatRed Hat AI Inference Server
Red HatRed Hat OpenShift AI (RHOAI)
Red HatRed Hat Enterprise Linux 10
Red HatRed Hat Enterprise Linux 9
Red HatRed Hat OpenShift AI 3.5
Red HatRed Hat Hardened Images
Red HatRed Hat AI Inference Server 3.2
Red HatRed Hat Enterprise Linux AI 3.3 for RHEL 9
Red HatRed Hat Enterprise Linux AI 3.4 for RHEL 9
Red HatRed Hat Enterprise Linux AI 3.5 for RHEL 9
SubsystemsGeneral OT
SectorsMultiple

What to Know

An arbitrary address write vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows an attacker to inject an arbitrary pointer into the cyclic refresh map field via crafted image pixel values. The encoder then writes approximately 1,200 bytes at the attacker-controlled address. This is fully deterministic and does not require a separate information leak. An attacker who can supply frames to a network-facing libaom encoder with SVC enabled could exploit this for denial of service or potential code execution. (NVD)

What to Do

Monitor Red Hat's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-56209
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-56209